Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Alles rund um Mac OSX & Linux (https://www.trojaner-board.de/alles-rund-um-mac-osx-linux/)
-   -   Linux: Bootkit Nemesis- Bios/Firmware Malware im VBR (https://www.trojaner-board.de/176707-linux-bootkit-nemesis-bios-firmware-malware-vbr.html)

dennissteins 09.03.2016 11:26

Linux: Bootkit Nemesis- Bios/Firmware Malware im VBR
 
Ich geb mein bestes, unter den Bedingungen ist es nicht so einfach. Passwörter werden geändert, Logs manipuliert, Accounts gelöscht...

Linux Ubuntu- chkrootkit

Code:

ROOTDIR is `/'
Checking `amd'...                                          not found
Checking `basename'...                                      not infected
Checking `biff'...                                          not found
Checking `chfn'...                                          not infected
Checking `chsh'...                                          not infected
Checking `cron'...                                          not infected
Checking `crontab'...                                      not infected
Checking `date'...                                          not infected
Checking `du'...                                            not infected
Checking `dirname'...                                      not infected
Checking `echo'...                                          not infected
Checking `egrep'...                                        not infected
Checking `env'...                                          not infected
Checking `find'...                                          not infected
Checking `fingerd'...                                      not found
Checking `gpm'...                                          not found
Checking `grep'...                                          not infected
Checking `hdparm'...                                        not infected
Checking `su'...                                            not infected
Checking `ifconfig'...                                      not infected
Checking `inetd'...                                        not infected
Checking `inetdconf'...                                    not found
Checking `identd'...                                        not found
Checking `init'...                                          not infected
Checking `killall'...                                      not infected
Checking `ldsopreload'...                                  not infected
Checking `login'...                                        not infected
Checking `ls'...                                            not infected
Checking `lsof'...                                          not infected
Checking `mail'...                                          not infected
Checking `mingetty'...                                      not found
Checking `netstat'...                                      not infected
Checking `named'...                                        not found
Checking `passwd'...                                        not infected
Checking `pidof'...                                        not infected
Checking `pop2'...                                          not found
Checking `pop3'...                                          not found
Checking `ps'...                                            not infected
Checking `pstree'...                                        not infected
Checking `rpcinfo'...                                      not found
Checking `rlogind'...                                      not found
Checking `rshd'...                                          not found
Checking `slogin'...                                        not infected
Checking `sendmail'...                                      not infected
Checking `sshd'...                                          not found
Checking `syslogd'...                                      not tested
Checking `tar'...                                          not infected
Checking `tcpd'...                                          not infected
Checking `tcpdump'...                                      not infected
Checking `top'...                                          not infected
Checking `telnetd'...                                      not found
Checking `timed'...                                        not found
Checking `traceroute'...                                    not found
Checking `vdir'...                                          not infected
Checking `w'...                                            not infected
Checking `write'...                                        not infected
Checking `aliens'...                                        no suspect files
Searching for sniffer's logs, it may take a while...        nothing found
Searching for rootkit HiDrootkit's default files...        nothing found
Searching for rootkit t0rn's default files...              nothing found
Searching for t0rn's v8 defaults...                        nothing found
Searching for rootkit Lion's default files...              nothing found
Searching for rootkit RSHA's default files...              nothing found
Searching for rootkit RH-Sharpe's default files...          nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found: 
/usr/lib/python2.7/dist-packages/PyQt4/uic/widget-plugins/.noinit /lib/modules/4.2.0-16-generic/vdso/.build-id
/lib/modules/4.2.0-16-generic/vdso/.build-id
Searching for LPD Worm files and dirs...                    nothing found
Searching for Ramen Worm files and dirs...                  nothing found
Searching for Maniac files and dirs...                      nothing found
Searching for RK17 files and dirs...                        nothing found
Searching for Ducoci rootkit...                            nothing found
Searching for Adore Worm...                                nothing found
Searching for ShitC Worm...                                nothing found
Searching for Omega Worm...                                nothing found
Searching for Sadmind/IIS Worm...                          nothing found
Searching for MonKit...                                    nothing found
Searching for Showtee...                                    nothing found
Searching for OpticKit...                                  nothing found
Searching for T.R.K...                                      nothing found
Searching for Mithra...                                    nothing found
Searching for LOC rootkit...                                nothing found
Searching for Romanian rootkit...                          nothing found
Searching for Suckit rootkit...                            nothing found
Searching for Volc rootkit...                              nothing found
Searching for Gold2 rootkit...                              nothing found
Searching for TC2 Worm default files and dirs...            nothing found
Searching for Anonoying rootkit default files and dirs...  nothing found
Searching for ZK rootkit default files and dirs...          nothing found
Searching for ShKit rootkit default files and dirs...      nothing found
Searching for AjaKit rootkit default files and dirs...      nothing found
Searching for zaRwT rootkit default files and dirs...      nothing found
Searching for Madalin rootkit default files...              nothing found
Searching for Fu rootkit default files...                  nothing found
Searching for ESRK rootkit default files...                nothing found
Searching for rootedoor...                                  nothing found
Searching for ENYELKM rootkit default files...              nothing found
Searching for common ssh-scanners default files...          nothing found
Searching for Linux/Ebury - Operation Windigo ssh...        Possible Linux/Ebury - Operation Windigo installetd
Searching for 64-bit Linux Rootkit ...                      nothing found
Searching for 64-bit Linux Rootkit modules...              nothing found
Searching for suspect PHP files...                          nothing found
Searching for anomalies in shell history files...          nothing found
Checking `asp'...                                          not infected
Checking `bindshell'...                                    not infected
Checking `lkm'...                                          chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'...                                      not found
Checking `sniffer'...                                      lo: not promisc and no packet sniffer sockets
Checking `w55808'...                                        not infected
Checking `wted'...                                          chkwtmp: nothing deleted
Checking `scalper'...                                      not infected
Checking `slapper'...                                      not infected
Checking `z2'...                                            user bbs deleted or never logged from lastlog!
Checking `chkutmp'...                                        The tty of the following user process(es) were not found
 in /var/run/utmp !
! RUID          PID TTY    CMD
! root          808 tty7  /usr/bin/X -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
chkutmp: nothing deleted
Checking `OSX_RSPLUG'...                                    not infected

Linux Ubuntu- Lynis

Code:

[+] Initializing program
------------------------------------

      Warning: PID file exists, probably another Lynis process is running.
      ------------------------------------------------------------------------------
      If you are unsure another Lynis process is running currently, you are adviced
      to stop current process and check the process list first. If you cancelled
      (by using CTRL+C) a previous instance, you can ignore this message.
     
      You are adviced to check for temporary files after program completion.
      ------------------------------------------------------------------------------

      Note: Cancelling the program can leave temporary files behind


[ Press [ENTER] to continue, or [CTRL]+C to stop ]

  - Detecting OS...                                          [ DONE ]

  ---------------------------------------------------
  Program version:          2.1.1
  Operating system:          Linux
  Operating system name:    Ubuntu
  Operating system version:  15.10
  Kernel version:            4.2.0
  Hardware platform:        x86_64
  Hostname:                  bbs-HP-280-G1-MT
  Auditor:                  [Unknown]
  Profile:                  /etc/lynis/default.prf
  Log file:                  /var/log/lynis.log
  Report file:              /var/log/lynis-report.dat
  Report version:            1.0
  Plugin directory:          /etc/lynis/plugins
  ---------------------------------------------------
  - Checking profile file (/etc/lynis/default.prf)...
  - Program update status...                                  [ NO UPDATE ]

[+] System Tools
------------------------------------
  - Scanning available tools...
  - Checking system binaries...

[+] Plugins (phase 1)
------------------------------------
 Note: plugins have more extensive tests, which may take a few minutes to complete
 
  - Plugin: debian
    [
[+] Debian Tests
------------------------------------
  - Checking for system binaries that are required by Debian Tests...[-8C
    - Checking /bin...                                        [ FOUND ]
    - Checking /sbin...                                      [ FOUND ]
    - Checking /usr/bin...                                    [ FOUND ]
    - Checking /usr/sbin...                                  [ FOUND ]
    - Checking /usr/local/bin...                              [ FOUND ]
    - Checking /usr/local/sbin...                            [ FOUND ]
  - Authentication:
    - PAM (Pluggable Authentication Modules):
      - libpam-tmpdir                                        [ Not Installed ]
      - libpam-usb                                            [ Not Installed ]
  - File System Checks:
    - DM-Crypt, Cryptsetup & Cryptmount:
      - Checking / on /dev/mapper/sda5_crypt                  [ ENCRYPTED (Type: LUKS1) ]
      - Checking /boot on /dev/sda1                          [ NOT ENCRYPTED ]
    - Ecryptfs                                                [ INSTALLED ]
      - Home for bbs                                          [ YES ]
  - Software:
    - apt-listbugs                                            [ Not Installed ]
    - apt-listchanges                                        [ Not Installed ]
    - checkrestart                                            [ Not Installed ]
    - debsecan                                                [ Not Installed ]
    - debsums                                                [ Not Installed ]
    - fail2ban                                                [ Not Installed ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]

]

[+] Boot and services
------------------------------------
  - Service Manager                                          [ UNKNOWN ]
    - Checking presence GRUB2                                [ FOUND ]
    - Checking for password protection                        [ WARNING ]
  - Check running services (systemctl)                        [ DONE ]
        Result: found 30 running services
  - Check enabled services at boot (systemctl)                [ DONE ]
        Result: found 46 enabled services
  - Check startup files (permissions)                        [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Kernel
------------------------------------
  - Checking default run level                                [ RUNLEVEL 5 ]
  - Checking CPU support (NX/PAE)
    CPU support: PAE and/or NoeXecute supported              [ FOUND ]
  - Checking kernel version and release                      [ DONE ]
  - Checking kernel type                                      [ DONE ]
  - Checking loaded kernel modules                            [ DONE ]
      Found 92 active modules
  - Checking Linux kernel configuration file                  [ FOUND ]
  - Checking default I/O kernel scheduler                    [ FOUND ]
  - Checking for available kernel update                      [ OK ]
  - Checking core dumps configuration                        [ DISABLED ]
    - Checking setuid core dumps configuration                [ PROTECTED ]
  - Check if reboot is needed                                [ NO ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Memory and processes
------------------------------------
  - Checking /proc/meminfo                                    [ FOUND ]
  - Searching for dead/zombie processes                      [ WARNING ]
  - Searching for IO waiting processes                        [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Users, Groups and Authentication
------------------------------------
  - Search administrator accounts                            [ OK ]
  - Checking for non-unique UIDs                              [ OK ]
  - Checking consistency of group files (grpck)              [ OK ]
  - Checking non unique group ID's                            [ OK ]
  - Checking non unique group names                          [ OK ]
  - Checking password file consistency                        [ OK ]
  - Query system users (non daemons)                          [ DONE ]
  - Checking NIS+ authentication support                      [ NOT ENABLED ]
  - Checking NIS authentication support                      [ NOT ENABLED ]
  - Checking sudoers file                                    [ FOUND ]
    - Check sudoers file permissions                          [ OK ]
  - Checking PAM password strength tools                      [ SUGGESTION ]
  - Checking PAM configuration files (pam.conf)              [ FOUND ]
  - Checking PAM configuration files (pam.d)                  [ FOUND ]
  - Checking PAM modules                                      [ FOUND ]
  - Checking LDAP module in PAM                              [ NOT FOUND ]
  - Checking accounts without expire date                    [ OK ]
  - Checking accounts without password                        [ OK ]
  - Checking user password aging                              [ DISABLED ]
  - Determining default umask
    - Checking umask (/etc/profile)                          [ OK ]
    - Checking umask (/etc/login.defs)                        [ SUGGESTION ]
    - Checking umask (/etc/init.d/rc)                        [ SUGGESTION ]
  - Checking LDAP authentication support                      [ NOT ENABLED ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Shells
------------------------------------
  - Checking shells from /etc/shells
    Result: found 4 shells (valid shells: 4).
    - Session timeout settings/tools                          [ NONE ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] File systems
------------------------------------
  - Checking mount points
    - Checking /home mount point                              [ OK ]
    - Checking /tmp mount point                              [ SUGGESTION ]
    - Checking /var mount point                              [ SUGGESTION ]
  - Checking LVM volume groups                                [ FOUND ]
    - Checking LVM volumes                                    [ FOUND ]
  - Querying FFS/UFS mount points (fstab)                    [ NONE ]
  - Query swap partitions (fstab)                            [ OK ]
  - Testing swap partitions                                  [ OK ]
  - Checking for old files in /tmp                            [ OK ]
  - Checking /tmp sticky bit                                  [ OK ]
  - ACL support root file system                              [ ENABLED ]
  - Checking Locate database                                  [ FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Storage
------------------------------------
  - Checking usb-storage driver (modprobe config)            [ NOT DISABLED ]
  - Checking firewire ohci driver (modprobe config)          [ DISABLED ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] NFS
------------------------------------
  - Check running NFS daemon                                  [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Name services
------------------------------------
  - Checking default DNS search domain                        [ NONE ]
  - Checking search domains                                  [ FOUND ]
  - Checking /etc/resolv.conf options                        [ NONE ]
  - Searching DNS domain name                                [ FOUND ]
      Domain name: bbs-HP-280-G1-MT
  - Checking nscd status                                      [ NOT FOUND ]
  - Checking BIND status                                      [ NOT FOUND ]
  - Checking PowerDNS status                                  [ NOT FOUND ]
  - Checking ypbind status                                    [ NOT FOUND ]
  - Checking /etc/hosts
    - Checking /etc/hosts (duplicates)                        [ OK ]
    - Checking /etc/hosts (hostname)                          [ OK ]
    - Checking /etc/hosts (localhost)                        [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Ports and packages
------------------------------------
  - Searching package managers
    - Searching dpkg package manager                          [ FOUND ]
      - Querying package manager


    - Query unpurged packages                                [ FOUND ]
  - Checking security repository in sources.list file        [ OK ]
  - Checking APT package database                            [ OK ]
E: Could not get lock /var/lib/apt/lists/lock - open (11: Resource temporarily unavailable)
E: Unable to lock directory /var/lib/apt/lists/
  - Checking vulnerable packages                              [ OK ]
  - Checking upgradeable packages                            [ SKIPPED ]
  - Checking package audit tool                              [ INSTALLED ]
    Found: apt-check

[ Press [ENTER] to continue, or [CTRL]+C to stop ]

[+] Networking
------------------------------------
  - Checking configured nameservers
    - Testing nameservers
        Nameserver: 127.0.1.1                                [ OK ]
    - Minimal of 2 responsive nameservers                    [ WARNING ]
  - Checking default gateway                                  [ DONE ]
  - Getting listening ports (TCP/UDP)                        [ DONE ]
      * Found 12 ports
  - Checking promiscuous interfaces                          [ OK ]
  - Checking waiting connections                              [ OK ]
  - Checking status DHCP client                              [ RUNNING ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]

[+] Printers and Spools
------------------------------------
  - Checking cups daemon                                      [ RUNNING ]
  - Checking CUPS configuration file                          [ OK ]
    - File permissions                                        [ WARNING ]
  - Checking CUPS addresses/sockets                          [ FOUND ]
  - Checking lp daemon                                        [ NOT RUNNING ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: e-mail and messaging
------------------------------------
  - Checking Exim status                                      [ NOT FOUND ]
  - Checking Postfix status                                  [ NOT FOUND ]
  - Checking Qmail status                                    [ NOT FOUND ]
  - Checking Sendmail status                                  [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: firewalls
------------------------------------
  - Checking iptables kernel module                          [ FOUND ]
    - Checking for empty ruleset                              [ OK ]
    - Checking for unused rules                              [ WARNING ]
    - Checking pflogd status                                  [ NOT FOUND ]
  - Checking pf                                              [ NOT FOUND ]
  - Checking host based firewall                              [ ACTIVE ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: webserver
------------------------------------
  - Checking Apache                                          [ NOT FOUND ]
  - Checking nginx                                            [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] SSH Support
------------------------------------
  - Checking running SSH daemon                              [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] SNMP Support
------------------------------------
  - Checking running SNMP daemon                              [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Databases
------------------------------------
  - MySQL process status                                      [ NOT FOUND ]
  - PostgreSQL processes status                              [ NOT FOUND ]
  - Oracle processes status                                  [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] LDAP Services
------------------------------------
  - Checking OpenLDAP instance                                [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] PHP
------------------------------------
  - Checking PHP                                              [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Squid Support
------------------------------------
  - Checking running Squid daemon                            [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Logging and files
------------------------------------
  - Checking for a running log daemon                        [ OK ]
    - Checking Syslog-NG status                              [ NOT FOUND ]
    - Checking systemd journal status                        [ FOUND ]
    - Checking Metalog status                                [ NOT FOUND ]
    - Checking RSyslog status                                [ FOUND ]
    - Checking RFC 3195 daemon status                        [ NOT FOUND ]
    - Checking minilogd instances                            [ NOT FOUND ]
  - Checking logrotate presence                              [ OK ]
  - Checking log directories (static list)                    [ DONE ]
  - Checking open log files                                  [ DONE ]
  - Checking deleted files in use                            [ FILES FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Insecure services
------------------------------------
  - Checking inetd status                                    [ NOT ACTIVE ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Banners and identification
------------------------------------
  - /etc/motd                                                [ NOT FOUND ]
  - /etc/issue                                                [ FOUND ]
    - /etc/issue contents                                    [ WEAK ]
  - /etc/issue.net                                            [ FOUND ]
    - /etc/issue.net contents                                [ WEAK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Scheduled tasks
------------------------------------
  - Checking crontab/cronjob                                  [ DONE ]
  - Checking atd status                                      [ NOT RUNNING ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Accounting
------------------------------------
  - Checking accounting information                          [ NOT FOUND ]
  - Checking sysstat accounting data                          [ NOT FOUND ]
  - Checking auditd                                          [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Time and Synchronization
------------------------------------
  - Checking for a running NTP daemon or client              [ WARNING ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Cryptography
------------------------------------
  - Checking SSL certificate expiration                      [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Virtualization
------------------------------------

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Containers
------------------------------------

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Security frameworks
------------------------------------
  - Checking presence AppArmor                                [ FOUND ]
    - Checking AppArmor status                                [ ENABLED ]
  - Checking presence SELinux                                [ NOT FOUND ]
  - Checking presence grsecurity                              [ NOT FOUND ]
  - Checking for implemented MAC framework                    [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: file integrity
------------------------------------
  - Checking file integrity tools
  - Checking presence integrity tool                          [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: System tooling
------------------------------------
  - Checking automation tooling
  - Automation tooling                                        [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Software: Malware scanners
------------------------------------

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] File Permissions
------------------------------------
  - Starting file permissions check
    /etc/lilo.conf                                            [ NOT FOUND ]
    /root/.ssh                                                [ NOT FOUND ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Home directories
------------------------------------
  - Checking shell history files                              [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]


[+] Kernel Hardening
------------------------------------
  - Comparing sysctl key pairs with scan profile
    - kernel.core_uses_pid (exp: 1)                          [ DIFFERENT ]
    - kernel.ctrl-alt-del (exp: 0)                            [ OK ]
    - kernel.kptr_restrict (exp: 1)                          [ OK ]
    - kernel.sysrq (exp: 0)                                  [ DIFFERENT ]
    - net.ipv4.conf.all.accept_redirects (exp: 0)            [ OK ]
    - net.ipv4.conf.all.accept_source_route (exp: 0)          [ OK ]
    - net.ipv4.conf.all.bootp_relay (exp: 0)                  [ OK ]
    - net.ipv4.conf.all.forwarding (exp: 0)                  [ OK ]
    - net.ipv4.conf.all.log_martians (exp: 1)                [ DIFFERENT ]
    - net.ipv4.conf.all.mc_forwarding (exp: 0)                [ OK ]
    - net.ipv4.conf.all.proxy_arp (exp: 0)                    [ OK ]
    - net.ipv4.conf.all.rp_filter (exp: 1)                    [ OK ]
    - net.ipv4.conf.all.send_redirects (exp: 0)              [ DIFFERENT ]
    - net.ipv4.conf.default.accept_redirects (exp: 0)        [ OK ]
    - net.ipv4.conf.default.accept_source_route (exp: 0)      [ OK ]
    - net.ipv4.conf.default.log_martians (exp: 1)            [ DIFFERENT ]
    - net.ipv4.icmp_echo_ignore_broadcasts (exp: 1)          [ OK ]
    - net.ipv4.icmp_ignore_bogus_error_responses (exp: 1)    [ OK ]
    - net.ipv4.tcp_syncookies (exp: 1)                        [ DIFFERENT ]
    - net.ipv4.tcp_timestamps (exp: 0)                        [ DIFFERENT ]
    - net.ipv6.conf.all.accept_redirects (exp: 0)            [ OK ]
    - net.ipv6.conf.all.accept_source_route (exp: 0)          [ OK ]
    - net.ipv6.conf.default.accept_redirects (exp: 0)        [ OK ]
    - net.ipv6.conf.default.accept_source_route (exp: 0)      [ OK ]

[ Press [ENTER] to continue, or [CTRL]+C to stop ]

Linux Ubuntu- rkhunter
Code:


[ Rootkit Hunter version 1.4.2 ]

Checking rkhunter data files...
  Checking file mirrors.dat                                  [ No update ]
  Checking file programs_bad.dat                            [ Updated ]
  Checking file backdoorports.dat                            [ No update ]
  Checking file suspscan.dat                                [ No update ]
  Checking file i18n/cn                                      [ No update ]
  Checking file i18n/de                                      [ No update ]
  Checking file i18n/en                                      [ No update ]
/usr/bin/rkhunter: 7439: [: Binary: unexpected operator
  Checking file i18n/tr                                      [ No update ]
  Checking file i18n/tr.utf8                                [ No update ]
/usr/bin/rkhunter: 7439: [: Binary: unexpected operator
  Checking file i18n/zh                                      [ No update ]
  Checking file i18n/zh.utf8                                [ No update ]
bbs@bbs-HP-280-G1-MT:~$ sudo rkhunter -c
[ Rootkit Hunter version 1.4.2 ]

Checking system commands...

  Performing 'strings' command checks
    Checking 'strings' command                              [ OK ]

  Performing 'shared libraries' checks
    Checking for preloading variables                        [ None found ]
    Checking for preloaded libraries                        [ None found ]
    Checking LD_LIBRARY_PATH variable                        [ Not found ]

  Performing file properties checks
    Checking for prerequisites                              [ OK ]
    /usr/sbin/adduser                                        [ OK ]
    /usr/sbin/chroot                                        [ OK ]
    /usr/sbin/cron                                          [ OK ]
    /usr/sbin/groupadd                                      [ OK ]
    /usr/sbin/groupdel                                      [ OK ]
    /usr/sbin/groupmod                                      [ OK ]
    /usr/sbin/grpck                                          [ OK ]
    /usr/sbin/nologin                                        [ OK ]
    /usr/sbin/pwck                                          [ OK ]
    /usr/sbin/rsyslogd                                      [ OK ]
    /usr/sbin/tcpd                                          [ OK ]
    /usr/sbin/useradd                                        [ OK ]
    /usr/sbin/userdel                                        [ OK ]
    /usr/sbin/usermod                                        [ OK ]
    /usr/sbin/vipw                                          [ OK ]
    /usr/sbin/unhide-linux                                  [ OK ]
    /usr/sbin/unhide-posix                                  [ OK ]
    /usr/sbin/unhide-tcp                                    [ OK ]
    /usr/bin/awk                                            [ OK ]
    /usr/bin/basename                                        [ OK ]
    /usr/bin/chattr                                          [ OK ]
    /usr/bin/curl                                            [ OK ]
    /usr/bin/cut                                            [ OK ]
    /usr/bin/diff                                            [ OK ]
    /usr/bin/dirname                                        [ OK ]
    /usr/bin/dpkg                                            [ OK ]
    /usr/bin/dpkg-query                                      [ OK ]
    /usr/bin/du                                              [ OK ]
    /usr/bin/env                                            [ OK ]
    /usr/bin/file                                            [ OK ]
    /usr/bin/find                                            [ OK ]
    /usr/bin/GET                                            [ OK ]
    /usr/bin/groups                                          [ OK ]
    /usr/bin/head                                            [ OK ]
    /usr/bin/id                                              [ OK ]
    /usr/bin/killall                                        [ OK ]
    /usr/bin/last                                            [ OK ]
    /usr/bin/lastlog                                        [ OK ]
    /usr/bin/ldd                                            [ OK ]
    /usr/bin/less                                            [ OK ]
    /usr/bin/locate                                          [ OK ]
    /usr/bin/logger                                          [ OK ]
    /usr/bin/lsattr                                          [ OK ]
    /usr/bin/lsof                                            [ OK ]
    /usr/bin/mail                                            [ OK ]
    /usr/bin/md5sum                                          [ OK ]
    /usr/bin/mlocate                                        [ OK ]
    /usr/bin/newgrp                                          [ OK ]
    /usr/bin/passwd                                          [ OK ]
    /usr/bin/perl                                            [ OK ]
    /usr/bin/pgrep                                          [ OK ]
    /usr/bin/pkill                                          [ OK ]
    /usr/bin/pstree                                          [ OK ]
    /usr/bin/rkhunter                                        [ OK ]
    /usr/bin/runcon                                          [ OK ]
    /usr/bin/sha1sum                                        [ OK ]
    /usr/bin/sha224sum                                      [ OK ]
    /usr/bin/sha256sum                                      [ OK ]
    /usr/bin/sha384sum                                      [ OK ]
    /usr/bin/sha512sum                                      [ OK ]
    /usr/bin/size                                            [ OK ]
    /usr/bin/sort                                            [ OK ]
    /usr/bin/ssh                                            [ OK ]
    /usr/bin/stat                                            [ OK ]
    /usr/bin/strace                                          [ OK ]
    /usr/bin/strings                                        [ OK ]
    /usr/bin/sudo                                            [ OK ]
    /usr/bin/tail                                            [ OK ]
    /usr/bin/telnet                                          [ OK ]
    /usr/bin/test                                            [ OK ]
    /usr/bin/top                                            [ OK ]
    /usr/bin/touch                                          [ OK ]
    /usr/bin/tr                                              [ OK ]
    /usr/bin/uniq                                            [ OK ]
    /usr/bin/users                                          [ OK ]
    /usr/bin/vmstat                                          [ OK ]
    /usr/bin/w                                              [ OK ]
    /usr/bin/watch                                          [ OK ]
    /usr/bin/wc                                              [ OK ]
    /usr/bin/wget                                            [ OK ]
    /usr/bin/whatis                                          [ OK ]
    /usr/bin/whereis                                        [ OK ]
    /usr/bin/which                                          [ OK ]
    /usr/bin/who                                            [ OK ]
    /usr/bin/whoami                                          [ OK ]
    /usr/bin/unhide                                          [ OK ]
    /usr/bin/mawk                                            [ OK ]
    /usr/bin/lwp-request                                    [ OK ]
    /usr/bin/bsd-mailx                                      [ OK ]
    /usr/bin/telnet.netkit                                  [ OK ]
    /usr/bin/w.procps                                        [ OK ]
    /sbin/depmod                                            [ OK ]
    /sbin/fsck                                              [ OK ]
    /sbin/ifconfig                                          [ OK ]
    /sbin/ifdown                                            [ OK ]
    /sbin/ifup                                              [ OK ]
    /sbin/init                                              [ OK ]
    /sbin/insmod                                            [ OK ]
    /sbin/ip                                                [ OK ]
    /sbin/lsmod                                              [ OK ]
    /sbin/modinfo                                            [ OK ]
    /sbin/modprobe                                          [ OK ]
    /sbin/rmmod                                              [ OK ]
    /sbin/route                                              [ OK ]
    /sbin/runlevel                                          [ OK ]
    /sbin/sulogin                                            [ OK ]
    /sbin/sysctl                                            [ OK ]
    /bin/bash                                                [ OK ]
    /bin/cat                                                [ OK ]
    /bin/chmod                                              [ OK ]
    /bin/chown                                              [ OK ]
    /bin/cp                                                  [ OK ]
    /bin/date                                                [ OK ]
    /bin/df                                                  [ OK ]
    /bin/dmesg                                              [ OK ]
    /bin/echo                                                [ OK ]
    /bin/ed                                                  [ OK ]
    /bin/egrep                                              [ OK ]
    /bin/fgrep                                              [ OK ]
    /bin/fuser                                              [ OK ]
    /bin/grep                                                [ OK ]
    /bin/ip                                                  [ OK ]
    /bin/kill                                                [ OK ]
    /bin/less                                                [ OK ]
    /bin/login                                              [ OK ]
    /bin/ls                                                  [ OK ]
    /bin/lsmod                                              [ OK ]
    /bin/mktemp                                              [ OK ]
    /bin/more                                                [ OK ]
    /bin/mount                                              [ OK ]
    /bin/mv                                                  [ OK ]
    /bin/netstat                                            [ OK ]
    /bin/ping                                                [ OK ]
    /bin/ps                                                  [ OK ]
    /bin/pwd                                                [ OK ]
    /bin/readlink                                            [ OK ]
    /bin/sed                                                [ OK ]
    /bin/sh                                                  [ OK ]
    /bin/su                                                  [ OK ]
    /bin/touch                                              [ OK ]
    /bin/uname                                              [ OK ]
    /bin/which                                              [ OK ]
    /bin/kmod                                                [ OK ]
    /bin/systemd                                            [ OK ]
    /bin/systemctl                                          [ OK ]
    /bin/dash                                                [ OK ]
    /lib/systemd/systemd                                    [ OK ]

[Press <ENTER> to continue]


Checking for rootkits...

  Performing check of known rootkit files and directories
    55808 Trojan - Variant A                                [ Not found ]
    ADM Worm                                                [ Not found ]
    AjaKit Rootkit                                          [ Not found ]
    Adore Rootkit                                            [ Not found ]
    aPa Kit                                                  [ Not found ]
    Apache Worm                                              [ Not found ]
    Ambient (ark) Rootkit                                    [ Not found ]
    Balaur Rootkit                                          [ Not found ]
    BeastKit Rootkit                                        [ Not found ]
    beX2 Rootkit                                            [ Not found ]
    BOBKit Rootkit                                          [ Not found ]
    cb Rootkit                                              [ Not found ]
    CiNIK Worm (Slapper.B variant)                          [ Not found ]
    Danny-Boy's Abuse Kit                                    [ Not found ]
    Devil RootKit                                            [ Not found ]
    Dica-Kit Rootkit                                        [ Not found ]
    Dreams Rootkit                                          [ Not found ]
    Duarawkz Rootkit                                        [ Not found ]
    Enye LKM                                                [ Not found ]
    Flea Linux Rootkit                                      [ Not found ]
    Fu Rootkit                                              [ Not found ]
    Fuck`it Rootkit                                          [ Not found ]
    GasKit Rootkit                                          [ Not found ]
    Heroin LKM                                              [ Not found ]
    HjC Kit                                                  [ Not found ]
    ignoKit Rootkit                                          [ Not found ]
    IntoXonia-NG Rootkit                                    [ Not found ]
    Irix Rootkit                                            [ Not found ]
    Jynx Rootkit                                            [ Not found ]
    KBeast Rootkit                                          [ Not found ]
    Kitko Rootkit                                            [ Not found ]
    Knark Rootkit                                            [ Not found ]
    ld-linuxv.so Rootkit                                    [ Not found ]
    Li0n Worm                                                [ Not found ]
    Lockit / LJK2 Rootkit                                    [ Not found ]
    Mood-NT Rootkit                                          [ Not found ]
    MRK Rootkit                                              [ Not found ]
    Ni0 Rootkit                                              [ Not found ]
    Ohhara Rootkit                                          [ Not found ]
    Optic Kit (Tux) Worm                                    [ Not found ]
    Oz Rootkit                                              [ Not found ]
    Phalanx Rootkit                                          [ Not found ]
    Phalanx2 Rootkit                                        [ Not found ]
    Phalanx2 Rootkit (extended tests)                        [ Not found ]
    Portacelo Rootkit                                        [ Not found ]
    R3dstorm Toolkit                                        [ Not found ]
    RH-Sharpe's Rootkit                                      [ Not found ]
    RSHA's Rootkit                                          [ Not found ]
    Scalper Worm                                            [ Not found ]
    Sebek LKM                                                [ Not found ]
    Shutdown Rootkit                                        [ Not found ]
    SHV4 Rootkit                                            [ Not found ]
    SHV5 Rootkit                                            [ Not found ]
    Sin Rootkit                                              [ Not found ]
    Slapper Worm                                            [ Not found ]
    Sneakin Rootkit                                          [ Not found ]
    'Spanish' Rootkit                                        [ Not found ]
    Suckit Rootkit                                          [ Not found ]
    Superkit Rootkit                                        [ Not found ]
    TBD (Telnet BackDoor)                                    [ Not found ]
    TeLeKiT Rootkit                                          [ Not found ]
    T0rn Rootkit                                            [ Not found ]
    trNkit Rootkit                                          [ Not found ]
    Trojanit Kit                                            [ Not found ]
    Tuxtendo Rootkit                                        [ Not found ]
    URK Rootkit                                              [ Not found ]
    Vampire Rootkit                                          [ Not found ]
    VcKit Rootkit                                            [ Not found ]
    Volc Rootkit                                            [ Not found ]
    Xzibit Rootkit                                          [ Not found ]
    zaRwT.KiT Rootkit                                        [ Not found ]
    ZK Rootkit                                              [ Not found ]

[Press <ENTER> to continue]


  Performing additional rootkit checks
    Suckit Rookit additional checks                          [ OK ]
    Checking for possible rootkit files and directories      [ None found ]

    Checking for possible rootkit strings                    [ None found ]

  Performing malware checks
    Checking running processes for suspicious files          [ None found ]
    Checking for login backdoors                            [ None found ]
    Checking for suspicious directories                      [ None found ]
    Checking for sniffer log files                          [ None found ]
    Suspicious Shared Memory segments                        [ None found ]

  Performing Linux specific checks
    Checking loaded kernel modules                          [ OK ]
    Checking kernel module names                            [ OK ]

[Press <ENTER> to continue]

Checking the network...

  Performing checks on the network ports
    Checking for backdoor ports                              [ None found ]
    Checking for hidden ports                                [ None found ]

  Performing checks on the network interfaces
    Checking for promiscuous interfaces                      [ None found ]

Checking the local host...

  Performing system boot checks
    Checking for local host name                            [ Found ]
    Checking for system startup files                        [ Found ]
    Checking system startup files for malware                [ None found ]

  Performing group and account checks
    Checking for passwd file                                [ Found ]
    Checking for root equivalent (UID 0) accounts            [ None found ]
    Checking for passwordless accounts                      [ None found ]
    Checking for passwd file changes                        [ None found ]
    Checking for group file changes                          [ None found ]
    Checking root account shell history files                [ None found ]

  Performing system configuration file checks
    Checking for an SSH configuration file                  [ Not found ]
    Checking for a running system logging daemon            [ Found ]
    Checking for a system logging configuration file        [ Found ]
    Checking if syslog remote logging is allowed            [ Not allowed ]

  Performing filesystem checks
    Checking /dev for suspicious file types                  [ Warning ]
    Checking for hidden files and directories                [ None found ]

[Press <ENTER> to continue]



System checks summary
=====================

File properties checks...
    Files checked: 147
    Suspect files: 0

Rootkit checks...
    Rootkits checked : 365
    Possible rootkits: 0

Applications checks...
    All checks skipped

The system checks took: 44 seconds

All results have been written to the log file: /var/log/rkhunter.log

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)


dennissteins 09.03.2016 12:52

Linux Ubuntu- TIGER

Code:


Security scripts *** 3.2.3, 2008.09.10.09.30 ***
Wed Mar  9 12:01:08 CET 2016
12:01> Beginning security report for bbs-HP-280-G1-MT (x86_64 Linux 4.2.0-16-generic).

# Performing check of passwd files...
# Checking entries from /etc/passwd.
--WARN-- [pass013w] Username `root' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `daemon' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `bin' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `sys' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `sync' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass015w] Login ID sync does not have a valid shell (/bin/sync).

The listed login ID does not have a valid login program or shell.
Usually these are defined in /etc/shells.

--WARN-- [pass013w] Username `games' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `man' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `lp' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `mail' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `news' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `uucp' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `proxy' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `www-data' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `backup' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `list' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `irc' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `gnats' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `nobody' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `systemd-timesync' is not using an acceptable
password hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `systemd-network' is not using an acceptable
password hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `systemd-resolve' is not using an acceptable
password hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `systemd-bus-proxy' is not using an acceptable
password hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `syslog' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `messagebus' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `uuidd' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `avahi' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `whoopsie' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `avahi-autoipd' is not using an acceptable
password hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `dnsmasq' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `colord' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `hplip' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `kernoops' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass016w] User kernoops has / as home directory

The listed login ID should not have "/" (system root directory) as its
home drive. This is a possible security hole.

--WARN-- [pass013w] Username `pulse' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `rtkit' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `saned' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `usbmux' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `lightdm' is not using an acceptable password
hash (x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `bbs' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `smmta' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass013w] Username `smmsp' is not using an acceptable password hash
(x).

The listed username is not using an acceptable, cryptographic method
for the password hash.

--WARN-- [pass012w] Home directory /nonexistent exists multiple times (2) in
/etc/passwd.

The listed home directory is specified for multiple users. This can
lead to denial-of-service and unexpected resource usage (i.e. shell
initialization files, etc) if not corrected.

--WARN-- [pass012w] Home directory /run/systemd exists multiple times (2) in
/etc/passwd.

The listed home directory is specified for multiple users. This can
lead to denial-of-service and unexpected resource usage (i.e. shell
initialization files, etc) if not corrected.

--WARN-- [pass012w] Home directory /var/lib/sendmail exists multiple times (2)
in /etc/passwd.


The listed home directory is specified for multiple users. This can
lead to denial-of-service and unexpected resource usage (i.e. shell
initialization files, etc) if not corrected.

# Performing check of group files...

# Performing check of user accounts...
# Checking accounts from /etc/passwd.
--WARN-- [acc021w] Login ID avahi-autoipd appears to be a dormant account.

The listed login ID appears to be dormant.  Files in the home directory
of this user have not been modified in the specified period of time and
after investigation the account may need to be disabled.

--WARN-- [acc021w] Login ID dnsmasq appears to be a dormant account.

The listed login ID appears to be dormant.  Files in the home directory
of this user have not been modified in the specified period of time and
after investigation the account may need to be disabled.

--WARN-- [acc006w] Login ID mail's home directory (/var/mail) has group `4096'
and world write access.

The home directory of the listed login ID has group write permission,
world write permission or both enabled.  This allows new files to be
added (and existing files potentially removed) by others.  The write
permissions should be removed.

--WARN-- [acc022w] Login ID nobody home directory (/nonexistent) is not
accessible.


The listed login ID has a home directory which is not accessible.
This should be checked to see if this is due to networking problem for
remote home directories.  Without a valid home directory, the user will
end up with / as the home directory.

# Performing check of /etc/hosts.equiv and .rhosts files...

# Checking accounts from /etc/passwd...

# Performing check of .netrc files...

# Checking accounts from /etc/passwd...

# Performing common access checks for root (in /etc/default/login, /securetty, and /etc/ttytab...

# Performing check of PATH components...
--WARN-- [path009w] /etc/profile does not export an initial setting for PATH.

An initial setting of the PATH variable should be setup in the default
locations for shell login programs (/etc/profile, /etc/csh.login, etc.).

# Only checking user 'root'
--WARN-- [path002w] /usr/bin/bsd-write in root's PATH from default is not
owned by root (owned by tty).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/chage in root's PATH from default is not owned by
root (owned by shadow).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/crontab in root's PATH from default is not owned
by root (owned by crontab).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/dotlockfile in root's PATH from default is not
owned by root (owned by mail).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/expiry in root's PATH from default is not owned
by root (owned by shadow).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/locate in root's PATH from default is not owned
by root (owned by mlocate).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/lockfile in root's PATH from default is not owned
by root (owned by mail).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/mlocate in root's PATH from default is not owned
by root (owned by mlocate).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/ssh-agent in root's PATH from default is not
owned by root (owned by ssh).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/wall in root's PATH from default is not owned by
root (owned by tty).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/bin/write in root's PATH from default is not owned by
root (owned by tty).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/sbin/hoststat in root's PATH from default is not
owned by root (owned by smmsp).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/sbin/purgestat in root's PATH from default is not
owned by root (owned by smmsp).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/sbin/sendmail in root's PATH from default is not
owned by root (owned by smmsp).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/sbin/sendmail-msp in root's PATH from default is not
owned by root (owned by smmsp).

The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

--WARN-- [path002w] /usr/sbin/sendmail-mta in root's PATH from default is not
owned by root (owned by smmsp).


The indicated file is in root's PATH, but is not owned by root.
This can allow Trojan horse programs or viruses to be planted into these
executables and spread by `root'.  Often these executables are owned by
`bin', `uucp' or other system accounts.  If these commands are never
used by root, then this is not a problem.  If they are, you should
consider changing the owner to `root'. Because of SMI's recent decision
to install most /usr/sbin/* and /usr/bin/* executables as owned by `bin',
this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention
with printer (lp*) and rpm programs among others.  Changing ownership
in this case may be problematic.

# Performing check of anonymous FTP...

# Performing checks of mail aliases...
# Checking aliases from /etc/aliases.
# Checking aliases from .

# Performing check of `cron' entries...
--WARN-- [cron004w] Root crontab does not exist

There is no crontab for the superuser account this is not in itself an
error since many systems might ship without one and use other methods
(/etc/cron* files) to run programs as root. However, if there is no
method for root to run scripts some system checking scripts (like tiger)
might not get executed at all.

--WARN-- [cron005w] Use of cron is not restricted


Cron allows users to submit jobs for the system to do at a particular,
possibly recurring time.  It can be very useful, but also has a very
real potential for abuse by either users or system crackers.  Users can
be restricted to use cron by creating a /etc/cron.allow (holding only
system administrators) or a /etc/cron.deny file (listing which users are
not allowed access). Depending on the site configuration if none exist
either only root will be able to setup cron tasks or all users will be
permitted. In many systems the default is to allow access to all users.

# Performing check of 'services' ...
# Checking services from /etc/services.
--WARN-- [inet003w] The port for service pop-2 is also assigned to service
pop2.

The indicated port number is assigned to another service.  This indicates
either a misconfiguration in the services database, or a possible sign
of an intrusion. This should be checked and corrected.  If it is not
apparent why it is like this, the system should be checked for other
signs of intrusion.

--WARN-- [inet003w] The port for service x400-snd is also assigned to service
acr-nema.


The indicated port number is assigned to another service.  This indicates
either a misconfiguration in the services database, or a possible sign
of an intrusion. This should be checked and corrected.  If it is not
apparent why it is like this, the system should be checked for other
signs of intrusion.

# Performing NFS exports check...

# Performing check of system file permissions...
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/gen_mounts' is not executable (command GET_MOUNTS).


The indicated command does not exist or is not executable.  This indicates
a configuration error.

# Checking for known intrusion signs...
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/gen_mounts' is not executable (command GET_MOUNTS).


The indicated command does not exist or is not executable.  This indicates
a configuration error.

# Performing check for rookits...
# Running chkrootkit (/usr/sbin/chkrootkit) to perform further checks...
--WARN-- [rootkit004w] Chkrootkit has detected a possible rootkit installation
Possible Linux/Ebury - Operation Windigo installetd


The 'chkrootkit' program has detected a possible rootkit installation
A full analysis of the system is recommended to determine the presence
of further signs of intrusion since a rootkit might have been installed.

# Performing system specific checks...

# Performing check of root directory...

# Checking device permissions...
--WARN-- [dev003w] The directory /dev/block resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--WARN-- [dev003w] The directory /dev/char resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--WARN-- [dev003w] The directory /dev/cpu resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--FAIL-- [dev002f] /dev/fuse has world permissions

Devices that have improper (world) permissions might be accessed by any
system user. This might open security holes if these are shared devices
or hold binaries (disks for example). The administrator should properly
set device access (using group configuration to provide access to a
device to multiple users, for example).

--WARN-- [dev003w] The directory /dev/hugepages resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--FAIL-- [dev002f] /dev/kmsg has world permissions

Devices that have improper (world) permissions might be accessed by any
system user. This might open security holes if these are shared devices
or hold binaries (disks for example). The administrator should properly
set device access (using group configuration to provide access to a
device to multiple users, for example).

--WARN-- [dev003w] The directory /dev/mqueue resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--FAIL-- [dev002f] /dev/rfkill has world permissions

Devices that have improper (world) permissions might be accessed by any
system user. This might open security holes if these are shared devices
or hold binaries (disks for example). The administrator should properly
set device access (using group configuration to provide access to a
device to multiple users, for example).

--WARN-- [dev003w] The directory /dev/ubuntu-vg resides in a device directory.

There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

--WARN-- [dev003w] The directory /dev/vfio resides in a device directory.


There is a file in the devices directory which is a common file. Devices
directory should only hold special files although some systems have
directories and shell scripts in /dev. Please check your system's
documentation to determine if that file should be located there.

# Checking for existence of log files...
--FAIL-- [logf005f] Log file /var/log/wtmp permission should be 644

The log file does not have proper permissions set. It is recommended
that you change the permissions to those suggested for these file.

--FAIL-- [logf005f] Log file /var/run/utmp permission should be 644

The log file does not have proper permissions set. It is recommended
that you change the permissions to those suggested for these file.

--FAIL-- [logf007f] Log file /var/log/messages does not exist


The log file "messages" should exist to show a trace of the system
logs (including reboots and kernel messages), it is also often used by
the syslog daemon to log information. The contents of the "messages"
logfile depends upon the configuration of the syslog.conf and varies by
distribution and/or system administrator preference.  It might not exist
if you have configured your system to use a different file for logging
or if an intruder has tried to cover his tracks by removing it since
the messages file might contain bad login attempts from local users and
remote hosts.

# Checking for correct umask settings...
--FAIL-- [misc022f] The umask setting in /etc/profile is insecure


The umask setting in the configuration file is insecure.  Umask must be
set as to prevent public write (i.e. either 002 or 022).

# Checking listening processes
--WARN-- [lin003w] The process `NetworkMa' is listening on socket 18504 (raw6
on 18504 interface) is run by root.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `cupsd' is listening on socket TCP (0t0 on TCP
interface) is run by root.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `dhclient' is listening on socket UDP (0t0 on
UDP interface) is run by root.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `dnsmasq' is listening on socket TCP (0t0 on
TCP interface) is run by nobody.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `dnsmasq' is listening on socket UDP (0t0 on
UDP interface) is run by nobody.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `gdbus' is listening on socket 0t0 (22u on 0t0
interface) is run by 762.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `gmain' is listening on socket 0t0 (22u on 0t0
interface) is run by 760.

Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

--WARN-- [lin003w] The process `sendmail-' is listening on socket TCP (0t0 on
TCP interface) is run by root.


Processes that have not been run by a valid user are listening on
interfaces open to external networks. This processes might have been
run by a valid user and changed uids or might be rogue processes.

The list of valid users is defined in Tiger's configuration file (tigerrc)
variable 'Tiger_Listening_ValidUsers'. An incorrect definition there
might also lead to invalid reports and false positives.

To fix this issue, review the value of the configuration variable and
the user the process is associated to. Confirm if the process is running
and is necessary.

If the process is run by a system user, in order to prevent this process
from working, it is often necessary necessary to reconfigure the system
to prevent it from starting when the system boots. If this process is
run by a normal user you might need to review the processes started by
login scripts, desktop confiuration or periodic program execution.

Notice that sometimes services open sporadic UDP listeners to receive
DNS requests, if you receive reports on open UDP services that later on
are closed this might be a false positive.

You can fix these false positives by adjusting the tiger.ignore
configuration file.

# Checking sshd_config configuration files...
--FAIL-- [ssh005w] Cannot find a configuration file for SSH.


Can not find explanation for message-id ssh005w

# Performing common access checks for root...
--FAIL-- [netw020f] There is no /etc/ftpusers file.


There is no ftpusers configuration file. In some systems this might
enable all administrative users (low UID) to access the local FTP server
if it is enabled (some other systems might deprecate its use).  It is
recommended that administrative users are added into /etc/ftpusers if
you have a FTP server installed.

# Checking ntpd configuration...
--ERROR-- [init001e] Don't have required command NETSTAT.

The indicated variable, which should specifies the pathname to a command,
does not have a value. This message should not appear on platforms
for which support is listed.  If it does appear, then for the missing
commands, if you know the name of the command, then simply place it into
the environment and rerun the checking system.

setenv AWK /usr/bin/awk

./tiger

Or alternately, create a 'site' configuration file and insert an
assignment statement in there of the form:

AWK=/usr/bin/awk


--ERROR-- [init004e] `/usr/lib/tiger/systems/default/getdisks' is not executable (command GETDISKS).


The indicated command does not exist or is not executable.  This indicates
a configuration error.

# Performing check of embedded pathnames...
--WARN-- [embed001w] Path `/etc/mail/Makefile' contains `/etc/mail' which is
not owned by root (owned by smmsp).
Embedded references in: /usr/bin/mailq->/default(PATH)
/usr/sbin/mailstats->/default(PATH)
/usr/sbin/newaliases->/default(PATH)
/usr/sbin/runq->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed002w] Path `/etc/mail/Makefile' is not owned by root (owned by
smmsp).
Embedded references in: /usr/bin/mailq->/default(PATH)
/usr/sbin/mailstats->/default(PATH)
/usr/sbin/newaliases->/default(PATH)
/usr/sbin/runq->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

--WARN-- [embed001w] Path `/etc/mail/smrsh/mail.local' contains `/etc/mail'
which is not owned by root (owned by smmsp).
Embedded references in: /usr/sbin/sensible-mda->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed001w] Path `/etc/mail/smrsh/mail.local' contains
`/etc/mail/smrsh' which is not owned by root (owned by smmsp).
Embedded references in: /usr/sbin/sensible-mda->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed001w] Path `/etc/mail/smrsh/procmail' contains `/etc/mail'
which is not owned by root (owned by smmsp).
Embedded references in: /usr/sbin/sensible-mda->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed001w] Path `/etc/mail/smrsh/procmail' contains
`/etc/mail/smrsh' which is not owned by root (owned by smmsp).
Embedded references in: /usr/sbin/sensible-mda->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed002w] Path `/etc/mail/smrsh/procmail' is not owned by root
(owned by mail).
Embedded references in: /usr/sbin/sensible-mda->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

--WARN-- [embed001w] Path `/etc/mail/tls/starttls.m4' contains `/etc/mail'
which is not owned by root (owned by smmsp).
Embedded references in: /etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
/etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
/etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
/etc/mail/Makefile->/usr/sbin/runq->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed001w] Path `/etc/mail/tls/starttls.m4' contains `/etc/mail/tls'
which is not owned by root (owned by smmsp).
Embedded references in: /etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
/etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
/etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
/etc/mail/Makefile->/usr/sbin/runq->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated pathname to an executable contains a component which is
not owned by root.  This can enable an intruder to gain unauthorized
privileges if they are able to replace the binary.  See the 'rationale'
explanation for a discussion of the reasons that executables run by root
should be owned by root.

--WARN-- [embed002w] Path `/sbin/unix_chkpwd' is not owned by root (owned by
shadow).
Embedded references in: /usr/bin/ecryptfs-setup-private->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

--WARN-- [embed002w] Path `/usr/lib/sendmail' is not owned by root (owned by
smmsp).
Embedded references in: /usr/bin/bashbug->/default(PATH)
/usr/bin/perlbug->/default(PATH)
/usr/bin/perlthanks->/default(PATH)
/usr/sbin/checksendmail->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

--WARN-- [embed002w] Path `/usr/lib/sm.bin/mailstats' is not owned by root
(owned by smmsp).
Embedded references in: /usr/bin/mailq->/default(PATH)
/usr/sbin/mailstats->/default(PATH)
/usr/sbin/newaliases->/default(PATH)
/usr/sbin/runq->/default(PATH)

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

--WARN-- [embed002w] Path `/usr/lib/sm.bin/sendmail' is not owned by root
(owned by smmsp).
Embedded references in: /usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
/usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
/usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
/usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/runq->/default(PATH)
12:01> Security report completed for bbs-HP-280-G1-MT.

See the 'embed' explanation for an explanation of the format of the
embedded references.

The indicated executable is not owned by owned by root.  This can enable
an intruder to gain unauthorized privileges if they are able to overwrite
the executable.  See the 'rationale' explanation for a discussion of
the reasons that executables run by root should be owned by root.

Note that if the executable is setuid to a non-root ID, then the ownershop
should *NOT* be changed to root unless the setuid bit is also removed.

Linux Ubuntu- TIGER (kurzer Bericht)
Code:

Security scripts *** 3.2.3, 2008.09.10.09.30 ***
Wed Mar  9 11:58:23 CET 2016
11:58> Beginning security report for bbs-HP-280-G1-MT (x86_64 Linux 4.2.0-16-generic).

# Performing check of passwd files...
# Checking entries from /etc/passwd.
--WARN-- [pass013w] Username `root' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `daemon' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `bin' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `sys' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `sync' is not using an acceptable password hash
        (x).
--WARN-- [pass015w] Login ID sync does not have a valid shell (/bin/sync).
--WARN-- [pass013w] Username `games' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `man' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `lp' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `mail' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `news' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `uucp' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `proxy' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `www-data' is not using an acceptable password
        hash (x).
--WARN-- [pass013w] Username `backup' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `list' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `irc' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `gnats' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `nobody' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `systemd-timesync' is not using an acceptable
        password hash (x).
--WARN-- [pass013w] Username `systemd-network' is not using an acceptable
        password hash (x).
--WARN-- [pass013w] Username `systemd-resolve' is not using an acceptable
        password hash (x).
--WARN-- [pass013w] Username `systemd-bus-proxy' is not using an acceptable
        password hash (x).
--WARN-- [pass013w] Username `syslog' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `messagebus' is not using an acceptable password
        hash (x).
--WARN-- [pass013w] Username `uuidd' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `avahi' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `whoopsie' is not using an acceptable password
        hash (x).
--WARN-- [pass013w] Username `avahi-autoipd' is not using an acceptable
        password hash (x).
--WARN-- [pass013w] Username `dnsmasq' is not using an acceptable password
        hash (x).
--WARN-- [pass013w] Username `colord' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `hplip' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `kernoops' is not using an acceptable password
        hash (x).
--WARN-- [pass016w] User kernoops has / as home directory
--WARN-- [pass013w] Username `pulse' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `rtkit' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `saned' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `usbmux' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `lightdm' is not using an acceptable password
        hash (x).
--WARN-- [pass013w] Username `bbs' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `smmta' is not using an acceptable password hash
        (x).
--WARN-- [pass013w] Username `smmsp' is not using an acceptable password hash
        (x).
--WARN-- [pass012w] Home directory /nonexistent exists multiple times (2) in
        /etc/passwd.
--WARN-- [pass012w] Home directory /run/systemd exists multiple times (2) in
        /etc/passwd.
--WARN-- [pass012w] Home directory /var/lib/sendmail exists multiple times (2)
        in /etc/passwd.

# Performing check of group files...

# Performing check of user accounts...
# Checking accounts from /etc/passwd.
--WARN-- [acc021w] Login ID avahi-autoipd appears to be a dormant account.
--WARN-- [acc021w] Login ID dnsmasq appears to be a dormant account.
--WARN-- [acc006w] Login ID mail's home directory (/var/mail) has group `4096'
        and world write access.
--WARN-- [acc022w] Login ID nobody home directory (/nonexistent) is not
        accessible.

# Performing check of /etc/hosts.equiv and .rhosts files...

# Checking accounts from /etc/passwd...

# Performing check of .netrc files...

# Checking accounts from /etc/passwd...

# Performing common access checks for root (in /etc/default/login, /securetty, and /etc/ttytab...

# Performing check of PATH components...
--WARN-- [path009w] /etc/profile does not export an initial setting for PATH.
# Only checking user 'root'
--WARN-- [path002w] /usr/bin/bsd-write in root's PATH from default is not
        owned by root (owned by tty).
--WARN-- [path002w] /usr/bin/chage in root's PATH from default is not owned by
        root (owned by shadow).
--WARN-- [path002w] /usr/bin/crontab in root's PATH from default is not owned
        by root (owned by crontab).
--WARN-- [path002w] /usr/bin/dotlockfile in root's PATH from default is not
        owned by root (owned by mail).
--WARN-- [path002w] /usr/bin/expiry in root's PATH from default is not owned
        by root (owned by shadow).
--WARN-- [path002w] /usr/bin/locate in root's PATH from default is not owned
        by root (owned by mlocate).
--WARN-- [path002w] /usr/bin/lockfile in root's PATH from default is not owned
        by root (owned by mail).
--WARN-- [path002w] /usr/bin/mlocate in root's PATH from default is not owned
        by root (owned by mlocate).
--WARN-- [path002w] /usr/bin/ssh-agent in root's PATH from default is not
        owned by root (owned by ssh).
--WARN-- [path002w] /usr/bin/wall in root's PATH from default is not owned by
        root (owned by tty).
--WARN-- [path002w] /usr/bin/write in root's PATH from default is not owned by
        root (owned by tty).
--WARN-- [path002w] /usr/sbin/hoststat in root's PATH from default is not
        owned by root (owned by smmsp).
--WARN-- [path002w] /usr/sbin/purgestat in root's PATH from default is not
        owned by root (owned by smmsp).
--WARN-- [path002w] /usr/sbin/sendmail in root's PATH from default is not
        owned by root (owned by smmsp).
--WARN-- [path002w] /usr/sbin/sendmail-msp in root's PATH from default is not
        owned by root (owned by smmsp).
--WARN-- [path002w] /usr/sbin/sendmail-mta in root's PATH from default is not
        owned by root (owned by smmsp).

# Performing check of anonymous FTP...

# Performing checks of mail aliases...
# Checking aliases from /etc/aliases.
# Checking aliases from .

# Performing check of `cron' entries...
--WARN-- [cron004w] Root crontab does not exist
--WARN-- [cron005w] Use of cron is not restricted

# Performing check of 'services' ...
# Checking services from /etc/services.
--WARN-- [inet003w] The port for service pop-2 is also assigned to service
        pop2.
--WARN-- [inet003w] The port for service x400-snd is also assigned to service
        acr-nema.

# Performing NFS exports check...

# Performing check of system file permissions...
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/gen_mounts' is not executable (command GET_MOUNTS).

# Checking for known intrusion signs...
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/gen_mounts' is not executable (command GET_MOUNTS).

# Performing check for rookits...
# Running chkrootkit (/usr/sbin/chkrootkit) to perform further checks...
--WARN-- [rootkit004w] Chkrootkit has detected a possible rootkit installation
Possible Linux/Ebury - Operation Windigo installetd

# Performing system specific checks...

# Performing check of root directory...

# Checking device permissions...
--WARN-- [dev003w] The directory /dev/block resides in a device directory.
--WARN-- [dev003w] The directory /dev/char resides in a device directory.
--WARN-- [dev003w] The directory /dev/cpu resides in a device directory.
--FAIL-- [dev002f] /dev/fuse has world permissions
--WARN-- [dev003w] The directory /dev/hugepages resides in a device directory.
--FAIL-- [dev002f] /dev/kmsg has world permissions
--WARN-- [dev003w] The directory /dev/mqueue resides in a device directory.
--FAIL-- [dev002f] /dev/rfkill has world permissions
--WARN-- [dev003w] The directory /dev/ubuntu-vg resides in a device directory.
--WARN-- [dev003w] The directory /dev/vfio resides in a device directory.

# Checking for existence of log files...
--FAIL-- [logf005f] Log file /var/log/wtmp permission should be 644
--FAIL-- [logf005f] Log file /var/run/utmp permission should be 644
--FAIL-- [logf007f] Log file /var/log/messages does not exist

# Checking for correct umask settings...
--FAIL-- [misc022f] The umask setting in /etc/profile is insecure

# Checking listening processes
--WARN-- [lin003w] The process `NetworkMa' is listening on socket 18504 (raw6
        on 18504 interface) is run by root.
--WARN-- [lin003w] The process `cupsd' is listening on socket TCP (0t0 on TCP
        interface) is run by root.
--WARN-- [lin003w] The process `dhclient' is listening on socket UDP (0t0 on
        UDP interface) is run by root.
--WARN-- [lin003w] The process `dnsmasq' is listening on socket TCP (0t0 on
        TCP interface) is run by nobody.
--WARN-- [lin003w] The process `dnsmasq' is listening on socket UDP (0t0 on
        UDP interface) is run by nobody.
--WARN-- [lin003w] The process `gdbus' is listening on socket 0t0 (22u on 0t0
        interface) is run by 762.
--WARN-- [lin003w] The process `gmain' is listening on socket 0t0 (22u on 0t0
        interface) is run by 760.
--WARN-- [lin003w] The process `sendmail-' is listening on socket TCP (0t0 on
        TCP interface) is run by root.

# Checking sshd_config configuration files...
--FAIL-- [ssh005w] Cannot find a configuration file for SSH.

# Performing common access checks for root...
--FAIL-- [netw020f] There is no /etc/ftpusers file.

# Checking ntpd configuration...
--ERROR-- [init001e] Don't have required command NETSTAT.
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/getdisks' is not executable (command GETDISKS).

# Performing check of embedded pathnames...
--WARN-- [embed001w] Path `/etc/mail/Makefile' contains `/etc/mail' which is
        not owned by root (owned by smmsp).
        Embedded references in: /usr/bin/mailq->/default(PATH)
                                /usr/sbin/mailstats->/default(PATH)
                                /usr/sbin/newaliases->/default(PATH)
                                /usr/sbin/runq->/default(PATH)
--WARN-- [embed002w] Path `/etc/mail/Makefile' is not owned by root (owned by
        smmsp).
        Embedded references in: /usr/bin/mailq->/default(PATH)
                                /usr/sbin/mailstats->/default(PATH)
                                /usr/sbin/newaliases->/default(PATH)
                                /usr/sbin/runq->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/smrsh/mail.local' contains `/etc/mail'
        which is not owned by root (owned by smmsp).
        Embedded references in: /usr/sbin/sensible-mda->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/smrsh/mail.local' contains
        `/etc/mail/smrsh' which is not owned by root (owned by smmsp).
        Embedded references in: /usr/sbin/sensible-mda->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/smrsh/procmail' contains `/etc/mail'
        which is not owned by root (owned by smmsp).
        Embedded references in: /usr/sbin/sensible-mda->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/smrsh/procmail' contains
        `/etc/mail/smrsh' which is not owned by root (owned by smmsp).
        Embedded references in: /usr/sbin/sensible-mda->/default(PATH)
--WARN-- [embed002w] Path `/etc/mail/smrsh/procmail' is not owned by root
        (owned by mail).
        Embedded references in: /usr/sbin/sensible-mda->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/tls/starttls.m4' contains `/etc/mail'
        which is not owned by root (owned by smmsp).
        Embedded references in: /etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/runq->/default(PATH)
--WARN-- [embed001w] Path `/etc/mail/tls/starttls.m4' contains `/etc/mail/tls'
        which is not owned by root (owned by smmsp).
        Embedded references in: /etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
                                /etc/mail/Makefile->/usr/sbin/runq->/default(PATH)
--WARN-- [embed002w] Path `/sbin/unix_chkpwd' is not owned by root (owned by
        shadow).
        Embedded references in: /usr/bin/ecryptfs-setup-private->/default(PATH)
--WARN-- [embed002w] Path `/usr/lib/sendmail' is not owned by root (owned by
        smmsp).
        Embedded references in: /usr/bin/bashbug->/default(PATH)
                                /usr/bin/perlbug->/default(PATH)
                                /usr/bin/perlthanks->/default(PATH)
                                /usr/sbin/checksendmail->/default(PATH)
--WARN-- [embed002w] Path `/usr/lib/sm.bin/mailstats' is not owned by root
        (owned by smmsp).
        Embedded references in: /usr/bin/mailq->/default(PATH)
                                /usr/sbin/mailstats->/default(PATH)
                                /usr/sbin/newaliases->/default(PATH)
                                /usr/sbin/runq->/default(PATH)
--WARN-- [embed002w] Path `/usr/lib/sm.bin/sendmail' is not owned by root
        (owned by smmsp).
        Embedded references in: /usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/bin/mailq->/default(PATH)
                                /usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/mailstats->/default(PATH)
                                /usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/newaliases->/default(PATH)
                                /usr/share/sendmail/update_conf->/etc/mail/Makefile->/usr/sbin/runq->/default(PATH)
11:58> Security report completed for bbs-HP-280-G1-MT.

Hier auch nochmal eine kleine Gallerie:

Rootkit nimmt Kaspersy auseinander, Hooks
https://imageshack.com/i/plH73ZWZp


So oder ähnlich ist es mit fast alles Anti-Rootkit Tools
https://imageshack.com/i/pnwIDn4Bp

Zum Beispiel:
https://imageshack.com/i/plquSB0fj

https://imageshack.com/i/pnqFPbhUp


RougeKiller läuft meist stabil, findet aber auch i.d.r. nur "Hooks"
https://imageshack.com/i/pmclX1txj

Windows 10: Ein paar Minuten nach der Neuinstallation:
Das Rootkit hat schon alles vorbereitet, Win total maipuliert:

https://imageshack.com/i/plZKBi0fp

https://imageshack.com/i/poBZCsNGp

https://imageshack.com/i/poybuz6vp

Eine Zugangsmöglichkeit führt über einen installierten DRuckerserver
https://imageshack.com/i/pnTxTu5dp


Ein weiterer Zugriff ging über eine VOIP-Schwachstelle in der FritzBox,
wir hatten nie Telefone eingerichtet, schongar nicht mit Rufumleitung
https://imageshack.com/i/pmsY0RPWp

Meines Erachtens müssen dies die verstecketen Volumes sein (loop),
das Bild zeigt nämlich die Volumes auf der Festplatte; aber es dürfte gar keine geben, weil ich vorher
alle Partitionen mit DBAN gelöscht habe.

https://imageshack.com/i/pnK3lx4bj

Wenn man sich gegen die Malware wehrt, passiert bei den Security Suiten das:
https://imageshack.com/i/poe5pGywp

stephan65 11.03.2016 10:01

Ja das kenn ich. Diese Probleme hatte ich auch. Das einzige was da hilft sind zwei große Elektromagnete. Den einen an den eigenen Kopf halten und den anderen an den Rechner. Dabei leise oooooooooooooooohm singen. Das ganze 3 mal wiederholen.

_sTaNlEy_ 11.03.2016 12:57

Braucht es derartige Beiträge (@stephan65) wirklich?

felix1 12.03.2016 22:35

Zitat:

Zitat von _sTaNlEy_ (Beitrag 1569521)
Braucht es derartige Beiträge (@stephan65) wirklich?

Nach dem Sinnlosbeitrag des TO habe ich am Beitrag von stephan65 eigentlich nichts auszusetzen:rolleyes:

dennissteins 14.03.2016 10:52

Da ich mir ziemlich sicher bin, das die Malware auch auch Linux Systeme infiltriert, werde ich hier die Dokumentataion seperat für Ubuntu fortsetzten.
Un da ich mich erst ca. 6 Monate mit Linux beschäftige, wäre es super, wenn ihr mir helfen könntet "Auffälligkeiten" herauszustellen, die auf ein verstecktes Rootkit schließen lassen.
Bisher liegt eine eindeutige objektive Identifizierung noch nicht vor; mein Infektionsverdacht stützt sich eher auf die Summe viele "kleinerer" Auffälligkeiten. Ich werde das noch versuchen aufzuzeigen.


auth log

Code:

Mar 13 02:14:37 invisiblethings systemd-logind[728]: New seat seat0.
Mar 13 02:14:37 invisiblethings systemd-logind[728]: Watching system buttons on /dev/input/event2 (Power Button)
Mar 13 02:14:37 invisiblethings systemd-logind[728]: Watching system buttons on /dev/input/event3 (Video Bus)
Mar 13 02:14:37 invisiblethings systemd-logind[728]: Watching system buttons on /dev/input/event0 (Power Button)
Mar 13 02:14:37 invisiblethings systemd-logind[728]: Watching system buttons on /dev/input/event1 (Sleep Button)
Mar 13 02:14:41 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 02:14:41 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 02:14:41 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 02:14:41 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 02:14:41 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Mar 13 02:14:41 invisiblethings systemd-logind[728]: New session c1 of user lightdm.
Mar 13 02:14:41 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Mar 13 02:14:45 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 02:14:45 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 02:14:45 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 02:14:45 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 02:14:45 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 13 02:15:04 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.45" (uid=0 pid=1005 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.11" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 02:15:11 invisiblethings dbus[680]: [system] Failed to activate service 'org.bluez': timed out
Mar 13 02:15:11 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Mar 13 02:15:11 invisiblethings lightdm: pam_unix(lightdm:session): session opened for user adminroot by (uid=0)
Mar 13 02:15:11 invisiblethings systemd-logind[728]: New session c2 of user adminroot.
Mar 13 02:15:11 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user adminroot by (uid=0)
Mar 13 02:15:19 invisiblethings gnome-keyring-daemon[1236]: The Secret Service was already initialized
Mar 13 02:15:19 invisiblethings gnome-keyring-daemon[1236]: The PKCS#11 component was already initialized
Mar 13 02:15:19 invisiblethings gnome-keyring-daemon[1236]: The SSH agent was already initialized
Mar 13 02:15:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.66 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 02:15:43 invisiblethings dbus[680]: [system] Failed to activate service 'org.bluez': timed out
Mar 13 02:16:41 invisiblethings systemd-logind[728]: Removed session c1.
Mar 13 02:16:41 invisiblethings systemd: pam_unix(systemd-user:session): session closed for user lightdm
Mar 13 02:17:01 invisiblethings CRON[2127]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 02:17:01 invisiblethings CRON[2127]: pam_unix(cron:session): session closed for user root
Mar 13 02:45:48 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.45" (uid=0 pid=1005 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.11" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 02:48:07 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install synaptic
Mar 13 02:48:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:48:07 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:51:29 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.91 [/usr/bin/python3 /usr/bin/gnome-language-selector] (owned by unix-user:adminroot)
Mar 13 02:51:52 invisiblethings polkit-agent-helper-1[3628]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 02:51:52 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.91 [/usr/bin/python3 /usr/bin/gnome-language-selector] (owned by unix-user:adminroot)
Mar 13 02:55:26 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/passwd root
Mar 13 02:55:26 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:55:26 invisiblethings passwd[4900]: pam_ecryptfs: PAM passphrase change module retrieved a NULL passphrase; nothing to do
Mar 13 02:55:43 invisiblethings passwd[4900]: pam_unix(passwd:chauthtok): password changed for root
Mar 13 02:55:43 invisiblethings passwd[4900]: gkr-pam: couldn't update the login keyring password: no old password was entered
Mar 13 02:55:43 invisiblethings passwd[4900]: pam_ecryptfs: Passphrase file wrapped
Mar 13 02:55:43 invisiblethings passwd[4900]: pam_ecryptfs: PAM passphrase change module retrieved at least one NULL passphrase; nothing to do
Mar 13 02:55:43 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:57:22 invisiblethings polkit-agent-helper-1[4957]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 02:57:22 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 02:57:57 invisiblethings polkit-agent-helper-1[5399]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 02:57:57 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.change-repository for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 03:12:00 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.45" (uid=0 pid=1005 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.11" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 02:17:01 invisiblethings CRON[5969]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 02:17:01 invisiblethings CRON[5969]: pam_unix(cron:session): session closed for user root
Mar 13 02:18:50 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.45" (uid=0 pid=1005 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.11" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 02:19:22 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.45" (uid=0 pid=1005 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.11" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 02:19:47 invisiblethings polkit-agent-helper-1[6192]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 02:19:47 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.change-repository for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 02:20:22 invisiblethings polkit-agent-helper-1[6231]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 02:20:22 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 02:22:30 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 02:22:30 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 02:22:30 invisiblethings pkexec[6479]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 02:52:44 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables --list
Mar 13 02:52:44 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:52:45 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:53:49 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -F
Mar 13 02:53:49 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:53:49 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:54:20 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P INPUT DROP
Mar 13 02:54:20 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:54:20 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:54:36 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P OUTPUT DROP
Mar 13 02:54:36 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:54:36 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:54:49 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P FORWARD DROP
Mar 13 02:54:49 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:54:49 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:59:11 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service iptables save
Mar 13 02:59:11 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:59:11 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:59:29 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service iptables start
Mar 13 02:59:29 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 02:59:29 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6767:632871 (system bus name :1.144 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 02:59:29 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 02:59:29 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6767:632871 (system bus name :1.144, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:01:03 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables --list
Mar 13 03:01:03 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:01:03 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:01:49 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P OUTPUT ACCEPT
Mar 13 03:01:49 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:01:49 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:02:44 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6811:652385 (system bus name :1.167 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:02:53 invisiblethings polkit-agent-helper-1[6842]: pam_unix(polkit-1:auth): authentication failure; logname= uid=1000 euid=0 tty= ruser=adminroot rhost=  user=adminroot
Mar 13 03:03:06 invisiblethings polkit-agent-helper-1[6843]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:03:06 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.freedesktop.systemd1.manage-units for system-bus-name::1.168 [systemctl start iptables.service] (owned by unix-user:adminroot)
Mar 13 03:03:06 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6811:652385 (system bus name :1.167, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:03:36 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables --list
Mar 13 03:03:36 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:03:36 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:04:18 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A OUTPUT -o lo -j ACCEPT
Mar 13 03:04:18 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:04:18 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:04:52 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -i lo -j ACCEPT
Mar 13 03:04:52 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:04:52 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:06:51 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service iptables save
Mar 13 03:06:51 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:06:51 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:07:37 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service iptables stop
Mar 13 03:07:37 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:07:37 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6895:681692 (system bus name :1.174 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:07:37 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:07:37 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6895:681692 (system bus name :1.174, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:07:52 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables --list
Mar 13 03:07:52 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:07:52 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:09:32 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P INPUT ACCEPT
Mar 13 03:09:32 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:09:32 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:14:38 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 22 -j DROP
Mar 13 03:14:38 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:14:38 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:17:01 invisiblethings CRON[6959]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 03:17:01 invisiblethings CRON[6959]: pam_unix(cron:session): session closed for user root
Mar 13 03:20:04 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 512-j DROP
Mar 13 03:20:04 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:20:04 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:20:29 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 512 -j DROP
Mar 13 03:20:29 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:20:29 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:20:40 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 513 -j DROP
Mar 13 03:20:40 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:20:40 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:21:55 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 123 -j DROP
Mar 13 03:21:55 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:21:55 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:23:07 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 23 -j DROP
Mar 13 03:23:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:23:07 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:23:17 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 6000 -j DROP
Mar 13 03:23:17 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:23:17 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 03:24:44 invisiblethings sudo: adminroot : TTY=pts/16 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/nautilus
Mar 13 03:24:44 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 03:26:12 invisiblethings polkit-agent-helper-1[7488]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:26:12 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 03:26:58 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8175:797802 (system bus name :1.181 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:26:58 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:8175:797802 (system bus name :1.181, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:27:34 invisiblethings groupadd[9746]: group added to /etc/group: name=ntp, GID=129
Mar 13 03:27:35 invisiblethings groupadd[9746]: group added to /etc/gshadow: name=ntp
Mar 13 03:27:35 invisiblethings groupadd[9746]: new group: name=ntp, GID=129
Mar 13 03:27:35 invisiblethings useradd[9751]: new user: name=ntp, UID=120, GID=129, home=/home/ntp, shell=/bin/false
Mar 13 03:27:35 invisiblethings usermod[9756]: change user 'ntp' password
Mar 13 03:27:35 invisiblethings chage[9763]: changed password expiry for ntp
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:9779:801564 (system bus name :1.183 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:9779:801564 (system bus name :1.183, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:9816:801580 (system bus name :1.184 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:9816:801580 (system bus name :1.184, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:9839:801593 (system bus name :1.185 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:27:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:9839:801593 (system bus name :1.185, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:27:45 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:9929:802419 (system bus name :1.186 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:27:45 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:9929:802419 (system bus name :1.186, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:28:27 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 03:28:27 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 03:28:27 invisiblethings pkexec[11100]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 03:29:02 invisiblethings polkit-agent-helper-1[11659]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:29:02 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.freedesktop.systemtoolsbackends.set for system-bus-name::1.190 [mate-users-admin] (owned by unix-user:adminroot)
Mar 13 03:29:45 invisiblethings chpasswd[12506]: pam_ecryptfs: PAM passphrase change module retrieved a NULL passphrase; nothing to do
Mar 13 03:29:45 invisiblethings chpasswd[12506]: pam_unix(chpasswd:chauthtok): new password not acceptable
Mar 13 03:29:45 invisiblethings gpasswd[12575]: user adminroot added by root to group dialout
Mar 13 03:29:45 invisiblethings gpasswd[12641]: user adminroot added by root to group fax
Mar 13 03:29:46 invisiblethings gpasswd[12688]: user adminroot added by root to group floppy
Mar 13 03:29:46 invisiblethings gpasswd[13023]: user adminroot added by root to group tape
Mar 13 03:29:46 invisiblethings gpasswd[13524]: user adminroot added by root to group audio
Mar 13 03:29:46 invisiblethings gpasswd[13825]: user adminroot added by root to group video
Mar 13 03:29:47 invisiblethings gpasswd[14277]: user adminroot added by root to group netdev
Mar 13 03:29:47 invisiblethings gpasswd[14698]: user adminroot added by root to group scanner
Mar 13 03:30:10 invisiblethings gpasswd[15293]: user adminroot added by root to group systemd-bus-proxy
Mar 13 03:30:15 invisiblethings gpasswd[15301]: user adminroot added by root to group systemd-journal
Mar 13 03:30:19 invisiblethings gpasswd[15308]: user adminroot added by root to group systemd-network
Mar 13 03:30:23 invisiblethings gpasswd[15333]: user adminroot added by root to group tty
Mar 13 03:30:30 invisiblethings gpasswd[15402]: user adminroot added by root to group syslog
Mar 13 03:30:45 invisiblethings gpasswd[15508]: user adminroot added by root to group avahi
Mar 13 03:31:06 invisiblethings gpasswd[15518]: user adminroot added by root to group pulse-access
Mar 13 03:31:10 invisiblethings gpasswd[15525]: user adminroot removed by root from group sambashare
Mar 13 03:31:14 invisiblethings gpasswd[15531]: user adminroot added by root to group saned
Mar 13 03:31:19 invisiblethings gpasswd[15537]: user adminroot added by root to group shadow
Mar 13 03:31:27 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 03:31:27 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 03:31:27 invisiblethings pkexec[15550]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 03:31:35 invisiblethings gpasswd[15568]: user adminroot added by root to group root
Mar 13 03:32:00 invisiblethings usermod[15662]: change user 'adminroot' GID from '1000' to '0'
Mar 13 03:32:00 invisiblethings chpasswd[15668]: pam_ecryptfs: PAM passphrase change module retrieved a NULL passphrase; nothing to do
Mar 13 03:32:00 invisiblethings chpasswd[15668]: pam_unix(chpasswd:chauthtok): new password not acceptable
Mar 13 03:36:29 invisiblethings sudo: pam_unix(sudo:auth): conversation failed
Mar 13 03:36:29 invisiblethings sudo: pam_unix(sudo:auth): auth could not identify password for [adminroot]
Mar 13 03:36:30 invisiblethings sudo: pam_unix(sudo:auth): conversation failed
Mar 13 03:36:30 invisiblethings sudo: pam_unix(sudo:auth): auth could not identify password for [adminroot]
Mar 13 03:36:32 invisiblethings sudo: pam_unix(sudo:auth): conversation failed
Mar 13 03:36:32 invisiblethings sudo: pam_unix(sudo:auth): auth could not identify password for [adminroot]
Mar 13 03:38:21 invisiblethings polkit-agent-helper-1[16010]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:38:21 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 03:39:58 invisiblethings polkit-agent-helper-1[16102]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:39:58 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action com.ubuntu.softwareproperties.applychanges for system-bus-name::1.224 [/usr/bin/python3 /usr/bin/software-properties-gtk --open-tab 2 --toplevel 56623112] (owned by unix-user:adminroot)
Mar 13 03:40:29 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 03:40:29 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 03:40:29 invisiblethings pkexec[16126]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 03:43:26 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 03:43:26 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 03:43:26 invisiblethings pkexec[16269]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 03:43:45 invisiblethings polkit-agent-helper-1[16237]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:43:45 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.137 [/usr/bin/python3 /usr/bin/update-manager --no-update --no-focus-on-map] (owned by unix-user:adminroot)
Mar 13 03:44:38 invisiblethings polkit-agent-helper-1[16658]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:44:38 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.233 [/usr/bin/python3 /usr/bin/gnome-language-selector] (owned by unix-user:adminroot)
Mar 13 03:45:26 invisiblethings polkit-agent-helper-1[16678]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 03:45:26 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.102 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 03:45:37 invisiblethings dbus[680]: [system] Rejected send message, 7 matched rules; type="method_call", sender=":1.236" (uid=1000 pid=16691 comm="/usr/bin/python /usr/lib/ubuntu-sso-client/ubuntu-") interface="(unset)" member="Get" error name="(unset)" requested_reply="0" destination="org.freedesktop.NetworkManager" (uid=0 pid=677 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 03:49:13 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:24440:931216 (system bus name :1.239 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:13 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:24440:931216 (system bus name :1.239, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:24769:933834 (system bus name :1.240 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:24769:933834 (system bus name :1.240, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:24788:933845 (system bus name :1.241 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:24788:933845 (system bus name :1.241, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:24810:933883 (system bus name :1.242 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:39 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:24810:933883 (system bus name :1.242, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:43 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:25781:934296 (system bus name :1.244 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:43 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:25781:934296 (system bus name :1.244, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:45 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26189:934514 (system bus name :1.245 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:46 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26189:934514 (system bus name :1.245, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26214:934739 (system bus name :1.246 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26214:934739 (system bus name :1.246, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26233:934756 (system bus name :1.247 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26233:934756 (system bus name :1.247, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26252:934774 (system bus name :1.248 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26252:934774 (system bus name :1.248, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26271:934787 (system bus name :1.249 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26271:934787 (system bus name :1.249, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26290:934801 (system bus name :1.250 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26290:934801 (system bus name :1.250, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:48 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26309:934813 (system bus name :1.251 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26309:934813 (system bus name :1.251, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26328:934826 (system bus name :1.252 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26328:934826 (system bus name :1.252, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26347:934840 (system bus name :1.253 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26347:934840 (system bus name :1.253, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26366:934854 (system bus name :1.254 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26366:934854 (system bus name :1.254, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26385:934866 (system bus name :1.255 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26385:934866 (system bus name :1.255, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26404:934880 (system bus name :1.256 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26404:934880 (system bus name :1.256, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26423:934891 (system bus name :1.257 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26423:934891 (system bus name :1.257, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26442:934907 (system bus name :1.258 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26442:934907 (system bus name :1.258, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26461:934919 (system bus name :1.259 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26461:934919 (system bus name :1.259, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26480:934933 (system bus name :1.260 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26480:934933 (system bus name :1.260, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26499:934948 (system bus name :1.261 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26499:934948 (system bus name :1.261, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26518:934962 (system bus name :1.262 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26518:934962 (system bus name :1.262, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26537:934978 (system bus name :1.263 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26537:934978 (system bus name :1.263, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26556:934991 (system bus name :1.264 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26556:934991 (system bus name :1.264, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26576:935003 (system bus name :1.265 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:50 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26576:935003 (system bus name :1.265, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26595:935020 (system bus name :1.266 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26595:935020 (system bus name :1.266, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26614:935033 (system bus name :1.267 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26614:935033 (system bus name :1.267, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26634:935047 (system bus name :1.268 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26634:935047 (system bus name :1.268, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26654:935062 (system bus name :1.269 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26654:935062 (system bus name :1.269, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:26674:935076 (system bus name :1.270 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:26674:935076 (system bus name :1.270, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:49:59 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27191:935833 (system bus name :1.272 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:49:59 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27191:935833 (system bus name :1.272, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:25 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27548:938505 (system bus name :1.274 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:25 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27548:938505 (system bus name :1.274, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:26 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27567:938516 (system bus name :1.275 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:26 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27567:938516 (system bus name :1.275, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:26 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27594:938587 (system bus name :1.276 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:26 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27594:938587 (system bus name :1.276, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:29 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27668:938824 (system bus name :1.277 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:29 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27668:938824 (system bus name :1.277, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:29 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27687:938835 (system bus name :1.278 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:29 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27687:938835 (system bus name :1.278, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:43 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27920:940239 (system bus name :1.279 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:43 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27920:940239 (system bus name :1.279, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:43 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27939:940251 (system bus name :1.280 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:43 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27939:940251 (system bus name :1.280, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:50:43 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:27951:940304 (system bus name :1.281 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:50:44 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:27951:940304 (system bus name :1.281, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:51:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:28493:947560 (system bus name :1.282 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:51:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:28493:947560 (system bus name :1.282, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:51:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:28510:947574 (system bus name :1.283 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:51:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:28510:947574 (system bus name :1.283, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:51:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:28527:947595 (system bus name :1.284 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:51:57 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:28527:947595 (system bus name :1.284, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:52:00 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:28583:947972 (system bus name :1.285 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:52:00 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:28583:947972 (system bus name :1.285, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:52:24 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:32414:950391 (system bus name :1.286 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:52:24 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:32414:950391 (system bus name :1.286, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:04 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:7989:954325 (system bus name :1.288 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:04 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:7989:954325 (system bus name :1.288, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:04 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8009:954337 (system bus name :1.289 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:04 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.66 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8075:954655 (system bus name :1.291 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:8075:954655 (system bus name :1.291, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8112:954672 (system bus name :1.292 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:8112:954672 (system bus name :1.292, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8132:954682 (system bus name :1.293 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:07 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:8132:954682 (system bus name :1.293, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:09 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:8162:954879 (system bus name :1.296 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:09 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:8162:954879 (system bus name :1.296, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:18 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:11899:955786 (system bus name :1.297 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:18 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:11899:955786 (system bus name :1.297, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:18 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:11936:955803 (system bus name :1.298 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:18 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:11936:955803 (system bus name :1.298, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:19 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:11961:955913 (system bus name :1.299 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:11961:955913 (system bus name :1.299, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:11998:955927 (system bus name :1.300 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:11998:955927 (system bus name :1.300, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:12021:955940 (system bus name :1.301 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:12021:955940 (system bus name :1.301, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13595:957247 (system bus name :1.302 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13595:957247 (system bus name :1.302, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13632:957262 (system bus name :1.303 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13632:957262 (system bus name :1.303, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13655:957281 (system bus name :1.304 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:33 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13655:957281 (system bus name :1.304, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13725:957542 (system bus name :1.305 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13725:957542 (system bus name :1.305, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13762:957555 (system bus name :1.306 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13762:957555 (system bus name :1.306, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13782:957567 (system bus name :1.307 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:36 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13782:957567 (system bus name :1.307, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:37 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13821:957688 (system bus name :1.310 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:37 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13821:957688 (system bus name :1.310, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:37 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:13841:957699 (system bus name :1.311 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:38 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:13841:957699 (system bus name :1.311, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:55 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:21045:959489 (system bus name :1.317 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:55 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:21045:959489 (system bus name :1.317, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:55 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:21082:959507 (system bus name :1.318 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:21082:959507 (system bus name :1.318, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:21102:959519 (system bus name :1.319 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:21102:959519 (system bus name :1.319, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:53:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:21121:959562 (system bus name :1.321 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)


dennissteins 14.03.2016 10:53

auth logs2

Code:


Mar 13 03:53:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:21138:959571 (system bus name :1.322 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:53:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:21138:959571 (system bus name :1.322, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 03:55:28 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 03:55:28 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 03:55:28 invisiblethings pkexec[23758]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 13 03:56:39 invisiblethings systemd-logind[728]: System is rebooting.
Mar 13 03:58:10 invisiblethings systemd-logind[703]: New seat seat0.
Mar 13 03:58:10 invisiblethings systemd-logind[703]: Watching system buttons on /dev/input/event2 (Power Button)
Mar 13 03:58:10 invisiblethings systemd-logind[703]: Watching system buttons on /dev/input/event3 (Video Bus)
Mar 13 03:58:10 invisiblethings systemd-logind[703]: Watching system buttons on /dev/input/event0 (Power Button)
Mar 13 03:58:10 invisiblethings systemd-logind[703]: Watching system buttons on /dev/input/event1 (Sleep Button)
Mar 13 03:58:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 03:58:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 03:58:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 03:58:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 03:58:17 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Mar 13 03:58:17 invisiblethings systemd-logind[703]: New session c1 of user lightdm.
Mar 13 03:58:17 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Mar 13 03:58:21 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 03:58:21 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 03:58:21 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 03:58:21 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 03:58:21 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 13 03:58:38 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Mar 13 03:58:38 invisiblethings lightdm: pam_unix(lightdm:session): session opened for user adminroot by (uid=0)
Mar 13 03:58:38 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user adminroot by (uid=0)
Mar 13 03:58:38 invisiblethings systemd-logind[703]: New session c2 of user adminroot.
Mar 13 03:58:40 invisiblethings dbus[680]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.50" (uid=0 pid=1060 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.9" (uid=0 pid=696 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 03:58:44 invisiblethings gnome-keyring-daemon[1036]: The Secret Service was already initialized
Mar 13 03:58:44 invisiblethings gnome-keyring-daemon[1036]: The PKCS#11 component was already initialized
Mar 13 03:58:45 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.70 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 03:58:48 invisiblethings dbus[680]: [system] Failed to activate service 'org.bluez': timed out
Mar 13 04:00:17 invisiblethings systemd-logind[703]: Removed session c1.
Mar 13 04:00:17 invisiblethings systemd: pam_unix(systemd-user:session): session closed for user lightdm
Mar 13 04:07:23 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-session:c2 (system bus name :1.70, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 04:07:23 invisiblethings systemd-logind[703]: System is powering down.
Mar 13 04:07:23 invisiblethings systemd: pam_unix(systemd-user:session): session closed for user adminroot
Mar 13 10:46:47 invisiblethings systemd-logind[669]: New seat seat0.
Mar 13 10:46:47 invisiblethings systemd-logind[669]: Watching system buttons on /dev/input/event2 (Power Button)
Mar 13 10:46:47 invisiblethings systemd-logind[669]: Watching system buttons on /dev/input/event3 (Video Bus)
Mar 13 10:46:47 invisiblethings systemd-logind[669]: Watching system buttons on /dev/input/event0 (Power Button)
Mar 13 10:46:47 invisiblethings systemd-logind[669]: Watching system buttons on /dev/input/event1 (Sleep Button)
Mar 13 10:46:50 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 10:46:50 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 10:46:50 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 10:46:50 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 10:46:50 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Mar 13 10:46:50 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Mar 13 10:46:50 invisiblethings systemd-logind[669]: New session c1 of user lightdm.
Mar 13 10:46:52 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 10:46:52 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 10:46:52 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 10:46:52 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 10:46:52 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 13 10:47:15 invisiblethings lightdm: pam_unix(lightdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=  user=adminroot
Mar 13 10:47:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 13 10:47:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 13 10:47:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 13 10:47:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 13 10:47:17 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 13 10:47:17 invisiblethings dbus[674]: [system] Failed to activate service 'org.bluez': timed out
Mar 13 10:47:45 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Mar 13 10:47:45 invisiblethings lightdm: pam_unix(lightdm:session): session opened for user adminroot by (uid=0)
Mar 13 10:47:45 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user adminroot by (uid=0)
Mar 13 10:47:45 invisiblethings systemd-logind[669]: New session c2 of user adminroot.
Mar 13 10:47:46 invisiblethings gnome-keyring-daemon[995]: The Secret Service was already initialized
Mar 13 10:47:46 invisiblethings gnome-keyring-daemon[995]: The PKCS#11 component was already initialized
Mar 13 10:47:47 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.64 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:47:58 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 10:48:12 invisiblethings dbus[674]: [system] Failed to activate service 'org.bluez': timed out
Mar 13 10:48:50 invisiblethings systemd-logind[669]: Removed session c1.
Mar 13 10:49:11 invisiblethings polkit-agent-helper-1[4385]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 10:49:11 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.90 [/usr/bin/unity-scope-loader applications/applications.scope applications/scopes.scope commands.scope] (owned by unix-user:adminroot)
Mar 13 10:50:13 invisiblethings polkit-agent-helper-1[11163]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 10:50:13 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.gufw for unix-process:11093:29634 [/bin/sh /usr/bin/gufw] (owned by unix-user:adminroot)
Mar 13 10:50:13 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 10:50:13 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 10:50:13 invisiblethings pkexec[11124]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/gufw-pkexec adminroot]
Mar 13 10:50:25 invisiblethings polkit-agent-helper-1[13357]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 10:50:25 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 10:50:29 invisiblethings polkit-agent-helper-1[15083]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 10:50:29 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 10:56:01 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:17133:65069 (system bus name :1.100 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:56:01 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:17133:65069 (system bus name :1.100, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 10:57:01 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:20417:71054 (system bus name :1.103 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:57:01 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:20417:71054 (system bus name :1.103, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 10:57:01 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:20459:71071 (system bus name :1.104 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:57:01 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:20459:71071 (system bus name :1.104, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 10:57:01 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:20484:71086 (system bus name :1.105 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:57:02 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:20484:71086 (system bus name :1.105, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 10:57:51 invisiblethings su[23585]: Successful su for www-data by root
Mar 13 10:57:51 invisiblethings su[23585]: + ??? root:www-data
Mar 13 10:57:51 invisiblethings su[23585]: pam_unix(su:session): session opened for user www-data by (uid=0)
Mar 13 10:57:51 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user www-data by (uid=0)
Mar 13 10:57:51 invisiblethings systemd-logind[669]: New session c3 of user www-data.
Mar 13 10:57:51 invisiblethings su[23585]: pam_unix(su:session): session closed for user www-data
Mar 13 10:57:51 invisiblethings systemd-logind[669]: Removed session c3.
Mar 13 10:58:00 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:24268:76923 (system bus name :1.108 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 10:58:00 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:24268:76923 (system bus name :1.108, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 11:15:37 invisiblethings polkit-agent-helper-1[30075]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 11:15:37 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 11:16:18 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install encfs
Mar 13 11:16:18 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:16:21 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:16:41 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install encfs
Mar 13 11:16:41 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:16:55 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:17:01 invisiblethings CRON[4745]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 11:17:01 invisiblethings CRON[4745]: pam_unix(cron:session): session closed for user root
Mar 13 11:17:30 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/gpasswd -a adminroot fuse
Mar 13 11:17:30 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:17:30 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:17:44 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/newgrp fuse
Mar 13 11:17:44 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:17:44 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:18:02 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/gpasswd -a adminroot fuse
Mar 13 11:18:02 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:18:02 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:18:33 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install apturl
Mar 13 11:18:34 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:18:34 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:20:04 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install gnome-encfs-manager
Mar 13 11:20:04 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:20:04 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:21:58 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install gnome-encfs-manager
Mar 13 11:21:58 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 11:21:58 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 11:23:27 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.pkexec.synaptic for unix-process:17316:229423 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:adminroot)
Mar 13 11:23:27 invisiblethings pkexec[17322]: adminroot: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/sbin/synaptic]
Mar 13 11:24:32 invisiblethings polkit-agent-helper-1[19072]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 11:24:32 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 11:29:06 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30866:263553 (system bus name :1.120 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 11:29:06 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30866:263553 (system bus name :1.120, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 11:29:06 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30904:263609 (system bus name :1.121 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 11:29:07 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30904:263609 (system bus name :1.121, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 11:30:29 invisiblethings polkit-agent-helper-1[1671]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 11:30:29 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 12:17:01 invisiblethings CRON[30425]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 12:17:01 invisiblethings CRON[30425]: pam_unix(cron:session): session closed for user root
Mar 13 13:00:36 invisiblethings compiz: gkr-pam: unlocked login keyring
Mar 13 13:03:06 invisiblethings polkit-agent-helper-1[22892]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 13:03:06 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.change-repository for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 13:04:02 invisiblethings sudo: adminroot : TTY=pts/17 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 22 --sport 1024:65535 -j DROP
Mar 13 13:04:02 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 13:04:02 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 13:06:48 invisiblethings polkit-agent-helper-1[27940]: pam_unix(polkit-1:auth): authentication failure; logname= uid=1000 euid=0 tty= ruser=adminroot rhost=  user=adminroot
Mar 13 13:06:56 invisiblethings polkit-agent-helper-1[28146]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 13:06:56 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 13:08:28 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:595:859784 (system bus name :1.143 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:08:29 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:595:859784 (system bus name :1.143, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:10:19 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6535:870903 (system bus name :1.144 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:10:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6535:870903 (system bus name :1.144, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:10:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6557:870928 (system bus name :1.145 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:10:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6557:870928 (system bus name :1.145, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:10:20 invisiblethings groupadd[6594]: group added to /etc/group: name=vboxusers, GID=130
Mar 13 13:10:20 invisiblethings groupadd[6594]: group added to /etc/gshadow: name=vboxusers
Mar 13 13:10:20 invisiblethings groupadd[6594]: new group: name=vboxusers, GID=130
Mar 13 13:10:21 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6755:871033 (system bus name :1.146 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:10:21 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6755:871033 (system bus name :1.146, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:10:21 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6783:871057 (system bus name :1.147 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:10:21 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6783:871057 (system bus name :1.147, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:10:25 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6950:871447 (system bus name :1.148 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:10:25 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6950:871447 (system bus name :1.148, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:14:17 invisiblethings polkit-agent-helper-1[13808]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 13:14:17 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 13:16:51 invisiblethings sudo: adminroot : TTY=unknown ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/cryptkeeper
Mar 13 13:16:51 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Mar 13 13:17:01 invisiblethings CRON[18739]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 13:17:01 invisiblethings CRON[18739]: pam_unix(cron:session): session closed for user root
Mar 13 13:22:10 invisiblethings polkit-agent-helper-1[28411]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 13:22:10 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 13 13:29:01 invisiblethings polkit-agent-helper-1[9827]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 13:29:01 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:9804:982617 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:adminroot)
Mar 13 13:29:01 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 13:29:02 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 13:29:02 invisiblethings pkexec[9811]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/sbin/synaptic]
Mar 13 13:40:15 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:29582:1050376 (system bus name :1.162 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:22 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:29582:1050376 (system bus name :1.162, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:35 invisiblethings groupadd[30167]: group added to /etc/group: name=smmta, GID=131
Mar 13 13:40:35 invisiblethings groupadd[30167]: group added to /etc/gshadow: name=smmta
Mar 13 13:40:35 invisiblethings groupadd[30167]: new group: name=smmta, GID=131
Mar 13 13:40:35 invisiblethings useradd[30185]: new user: name=smmta, UID=121, GID=131, home=/var/lib/sendmail, shell=/bin/false
Mar 13 13:40:36 invisiblethings usermod[30205]: change user 'smmta' password
Mar 13 13:40:37 invisiblethings chage[30220]: changed password expiry for smmta
Mar 13 13:40:38 invisiblethings chfn[30238]: changed user 'smmta' information
Mar 13 13:40:38 invisiblethings groupadd[30288]: group added to /etc/group: name=smmsp, GID=132
Mar 13 13:40:38 invisiblethings groupadd[30288]: group added to /etc/gshadow: name=smmsp
Mar 13 13:40:38 invisiblethings groupadd[30288]: new group: name=smmsp, GID=132
Mar 13 13:40:38 invisiblethings useradd[30304]: new user: name=smmsp, UID=122, GID=132, home=/var/lib/sendmail, shell=/bin/false
Mar 13 13:40:39 invisiblethings usermod[30321]: change user 'smmsp' password
Mar 13 13:40:39 invisiblethings chage[30336]: changed password expiry for smmsp
Mar 13 13:40:39 invisiblethings chfn[30339]: changed user 'smmsp' information
Mar 13 13:40:42 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30469:1053132 (system bus name :1.163 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:42 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30469:1053132 (system bus name :1.163, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:42 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30497:1053163 (system bus name :1.164 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:42 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30497:1053163 (system bus name :1.164, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:44 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30593:1053333 (system bus name :1.165 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:44 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30593:1053333 (system bus name :1.165, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:44 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:30617:1053347 (system bus name :1.166 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:44 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:30617:1053347 (system bus name :1.166, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:31422:1053838 (system bus name :1.167 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:49 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:31422:1053838 (system bus name :1.167, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 13:40:49 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:31449:1053857 (system bus name :1.168 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 13:40:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:31449:1053857 (system bus name :1.168, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:00:03 invisiblethings CRON[10353]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 14:00:04 invisiblethings CRON[10353]: pam_unix(cron:session): session closed for user smmsp
Mar 13 14:00:49 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.apport.apport-gtk-root for unix-process:1002:15442 [/sbin/upstart --user] (owned by unix-user:adminroot)
Mar 13 14:00:49 invisiblethings pkexec[11680]: adminroot: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/share/apport/apport-gtk]
Mar 13 14:01:19 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:12763:1176865 (system bus name :1.174 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:01:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:12763:1176865 (system bus name :1.174, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:01:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:12838:1176983 (system bus name :1.175 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:01:20 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:12838:1176983 (system bus name :1.175, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:01:20 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:12870:1177012 (system bus name :1.176 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:01:21 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:12870:1177012 (system bus name :1.176, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:03:23 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:29883:1189263 (system bus name :1.180 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:03:23 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:29883:1189263 (system bus name :1.180, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:03:23 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:29908:1189287 (system bus name :1.181 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:03:23 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:29908:1189287 (system bus name :1.181, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:03:23 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:29952:1189316 (system bus name :1.182 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:03:24 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:29952:1189316 (system bus name :1.182, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:03:24 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:29977:1189334 (system bus name :1.183 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:03:27 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:29977:1189334 (system bus name :1.183, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:03:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:31676:1192048 (system bus name :1.184 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 14:03:51 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:31676:1192048 (system bus name :1.184, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 14:17:01 invisiblethings CRON[28159]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 14:17:01 invisiblethings CRON[28159]: pam_unix(cron:session): session closed for user root
Mar 13 14:20:01 invisiblethings CRON[2399]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 14:20:01 invisiblethings CRON[2399]: pam_unix(cron:session): session closed for user smmsp
Mar 13 14:40:02 invisiblethings CRON[12976]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 14:40:02 invisiblethings CRON[12976]: pam_unix(cron:session): session closed for user smmsp
Mar 13 14:47:39 invisiblethings compiz: gkr-pam: unlocked login keyring
Mar 13 14:49:27 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install fail2ban
Mar 13 14:49:27 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 14:49:32 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 14:49:46 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get autoremove
Mar 13 14:49:46 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 14:51:37 invisiblethings sudo: pam_unix(sudo:auth): authentication failure; logname=adminroot uid=1000 euid=0 tty=/dev/pts/20 ruser=adminroot rhost=  user=adminroot
Mar 13 14:51:51 invisiblethings sudo: adminroot : TTY=pts/20 ; PWD=/home/adminroot ; USER=root ; COMMAND=/etc/init.d/fail2ban
Mar 13 14:51:51 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 14:51:53 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 14:52:17 invisiblethings sudo: adminroot : TTY=pts/20 ; PWD=/home/adminroot ; USER=root ; COMMAND=/etc/init.d/fail2ban force-start
Mar 13 14:52:17 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 14:52:21 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 14:52:37 invisiblethings sudo: adminroot : TTY=pts/20 ; PWD=/home/adminroot ; USER=root ; COMMAND=/etc/init.d/fail2ban status
Mar 13 14:52:37 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 14:52:41 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 14:53:47 invisiblethings sudo: adminroot : TTY=unknown ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/geany /etc/fail2ban/jail.conf.
Mar 13 14:53:47 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Mar 13 14:57:30 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 14:58:29 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.193" (uid=1000 pid=2304 comm="/usr/lib/firefox/firefox ")
Mar 13 14:58:29 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.193" (uid=1000 pid=2304 comm="/usr/lib/firefox/firefox ")
Mar 13 15:00:01 invisiblethings CRON[19092]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 15:00:01 invisiblethings CRON[19093]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 15:00:04 invisiblethings CRON[19092]: pam_unix(cron:session): session closed for user smmsp
Mar 13 15:00:05 invisiblethings CRON[19093]: pam_unix(cron:session): session closed for user root
Mar 13 15:00:07 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/bin/cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
Mar 13 15:00:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:00:07 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:00:19 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/vi /etc/fail2ban/jail.local
Mar 13 15:00:19 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:01:51 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/geany /etc/fail2ban/jail.local
Mar 13 15:01:51 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:09:03 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service fail2ban restart
Mar 13 15:09:04 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:09:04 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:5667:1583296 (system bus name :1.195 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 15:09:08 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:09:08 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:5667:1583296 (system bus name :1.195, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 15:09:18 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:09:21 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service fail2ban restart
Mar 13 15:09:21 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:09:21 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:6268:1585058 (system bus name :1.196 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 15:09:21 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:6268:1585058 (system bus name :1.196, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 15:09:21 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:09:33 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/fail2ban-client status
Mar 13 15:09:33 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:09:33 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:09:47 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -L
Mar 13 15:09:47 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:09:47 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:12:04 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P INPUT DROP
Mar 13 15:12:04 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:12:04 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:12:16 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P FORWARD DROP
Mar 13 15:12:16 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:12:16 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:12:41 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -P OUTPUT ACCEPT
Mar 13 15:12:41 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:12:41 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:13:07 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
Mar 13 15:13:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:13:07 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:13:35 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Mar 13 15:13:35 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:13:35 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:14:45 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables -A INPUT -p tcp --dport 22 --sport 1:65535 -j DROP
Mar 13 15:14:46 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:14:46 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:15:59 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service fail2ban restart
Mar 13 15:15:59 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:15:59 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:32593:1624842 (system bus name :1.199 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 13 15:16:00 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:32593:1624842 (system bus name :1.199, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 15:16:00 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:16:21 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/bin/systemctl status fail2ban.service
Mar 13 15:16:21 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:16:21 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:17:01 invisiblethings CRON[5406]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 15:17:01 invisiblethings CRON[5406]: pam_unix(cron:session): session closed for user root
Mar 13 15:17:30 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service fail2ban enable
Mar 13 15:17:30 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:17:31 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:17:51 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/service fail2ban force-start
Mar 13 15:17:51 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:17:52 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:18:18 invisiblethings polkit-agent-helper-1[11301]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 13 15:18:18 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.gufw for unix-process:11044:1637914 [/bin/sh /usr/bin/gufw] (owned by unix-user:adminroot)
Mar 13 15:18:18 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 13 15:18:18 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 13 15:18:18 invisiblethings pkexec[11056]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/gufw-pkexec adminroot]
Mar 13 15:20:02 invisiblethings CRON[18942]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 15:21:03 invisiblethings CRON[18942]: pam_unix(cron:session): session closed for user smmsp
Mar 13 15:21:19 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/sbin/iptables --list
Mar 13 15:21:19 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:21:19 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:22:15 invisiblethings sudo: adminroot : TTY=pts/22 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/nautilus
Mar 13 15:22:15 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:23:11 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 15:40:05 invisiblethings CRON[5836]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 15:41:08 invisiblethings CRON[5836]: pam_unix(cron:session): session closed for user smmsp
Mar 13 15:41:40 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 15:42:01 invisiblethings sudo: adminroot : TTY=pts/19 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/tcpdump
Mar 13 15:42:01 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:44:06 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:44:09 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 15:45:50 invisiblethings sudo: pam_unix(sudo:auth): conversation failed
Mar 13 15:45:50 invisiblethings sudo: pam_unix(sudo:auth): auth could not identify password for [adminroot]
Mar 13 15:46:08 invisiblethings sudo: adminroot : TTY=pts/18 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/tcpdump -vv
Mar 13 15:46:08 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 13 15:51:46 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.pkexec.gufw for unix-process:7069:1839058 [/bin/sh /usr/bin/gufw] (owned by unix-user:adminroot)
Mar 13 15:51:46 invisiblethings pkexec[7078]: adminroot: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/gufw-pkexec adminroot]
Mar 13 15:53:54 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.213" (uid=1000 pid=8129 comm="gedit /home/adminroot/Schreibtisch/tcpdump ")
Mar 13 15:53:54 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.213" (uid=1000 pid=8129 comm="gedit /home/adminroot/Schreibtisch/tcpdump ")
Mar 13 15:57:44 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.216" (uid=1000 pid=8129 comm="gedit /home/adminroot/Schreibtisch/tcpdump ")
Mar 13 15:57:44 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.216" (uid=1000 pid=8129 comm="gedit /home/adminroot/Schreibtisch/tcpdump ")
Mar 13 16:00:01 invisiblethings CRON[1323]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 13 16:00:01 invisiblethings CRON[1322]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 13 16:00:04 invisiblethings CRON[1322]: pam_unix(cron:session): session closed for user smmsp
Mar 13 16:00:05 invisiblethings CRON[1323]: pam_unix(cron:session): session closed for user root
Mar 13 16:02:50 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.218" (uid=1000 pid=14296 comm="gedit /home/adminroot/Schreibtisch/Unbenanntes Dok")
Mar 13 16:02:50 invisiblethings dbus[674]: [system] Rejected send message, 9 matched rules; type="method_return", sender=":1.2" (uid=107 pid=665 comm="avahi-daemon: starting up ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.218" (uid=1000 pid=14296 comm="gedit /home/adminroot/Schreibtisch/Unbenanntes Dok")
Mar 13 16:04:12 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 16:04:23 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 16:04:26 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 13 16:04:32 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 16:04:35 invisiblethings dbus[674]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=1654 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=664 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 13 16:07:21 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-session:c2 (system bus name :1.64, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 13 16:07:26 invisiblethings systemd-logind[669]: Delay lock is active (UID 1000/adminroot, PID 1156/gnome-session) but inhibitor timeout is reached.
Mar 13 16:07:26 invisiblethings systemd-logind[669]: System is powering down.
Mar 14 00:44:38 invisiblethings systemd-logind[727]: New seat seat0.
Mar 14 00:44:38 invisiblethings systemd-logind[727]: Watching system buttons on /dev/input/event2 (Power Button)
Mar 14 00:44:38 invisiblethings systemd-logind[727]: Watching system buttons on /dev/input/event3 (Video Bus)
Mar 14 00:44:38 invisiblethings systemd-logind[727]: Watching system buttons on /dev/input/event0 (Power Button)
Mar 14 00:44:38 invisiblethings systemd-logind[727]: Watching system buttons on /dev/input/event1 (Sleep Button)
Mar 14 00:44:48 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 14 00:44:48 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 14 00:44:48 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 14 00:44:48 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 14 00:44:48 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Mar 14 00:44:48 invisiblethings systemd-logind[727]: New session c1 of user lightdm.
Mar 14 00:44:48 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Mar 14 00:44:53 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 14 00:44:53 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 14 00:44:53 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 14 00:44:53 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 14 00:44:53 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 14 00:45:16 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Mar 14 00:45:16 invisiblethings lightdm: pam_unix(lightdm:session): session opened for user adminroot by (uid=0)
Mar 14 00:45:16 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user adminroot by (uid=0)
Mar 14 00:45:16 invisiblethings systemd-logind[727]: New session c2 of user adminroot.
Mar 14 00:45:19 invisiblethings dbus[741]: [system] Failed to activate service 'org.bluez': timed out
Mar 14 00:45:22 invisiblethings gnome-keyring-daemon[1255]: The Secret Service was already initialized
Mar 14 00:45:22 invisiblethings gnome-keyring-daemon[1255]: The PKCS#11 component was already initialized
Mar 14 00:45:23 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.60 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 00:45:47 invisiblethings dbus[741]: [system] Failed to activate service 'org.bluez': timed out
Mar 14 00:46:32 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.apport.apport-gtk-root for unix-process:6585:15491 [update-notifier] (owned by unix-user:adminroot)
Mar 14 00:46:32 invisiblethings pkexec[7530]: adminroot: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/share/apport/apport-gtk]
Mar 14 00:46:47 invisiblethings polkit-agent-helper-1[8566]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 00:46:47 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.gufw for unix-process:8553:17296 [/bin/sh /usr/bin/gufw] (owned by unix-user:adminroot)
Mar 14 00:46:47 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 00:46:47 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 00:46:47 invisiblethings pkexec[8559]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/gufw-pkexec adminroot]
Mar 14 00:46:48 invisiblethings systemd-logind[727]: Removed session c1.
Mar 14 00:47:20 invisiblethings dbus[741]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.92" (uid=0 pid=13001 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.10" (uid=0 pid=788 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 14 00:54:01 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get clean
Mar 14 00:54:01 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:54:01 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 00:55:34 invisiblethings polkit-agent-helper-1[5326]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 00:55:34 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.95 [/usr/bin/python /usr/bin/software-center apt://encfs] (owned by unix-user:adminroot)
Mar 14 00:55:46 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/aptitude install encfs
Mar 14 00:55:46 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:55:49 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 00:55:54 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/aptitude install encfs
Mar 14 00:55:54 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:56:18 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 00:56:52 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/gpasswd -a adminroot fuse
Mar 14 00:56:52 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:56:52 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 00:57:20 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/newgrp fuse
Mar 14 00:57:20 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:57:20 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 00:57:43 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install cryptkeeper
Mar 14 00:57:43 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 00:57:52 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:00:01 invisiblethings CRON[2986]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 14 01:00:01 invisiblethings CRON[2985]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 14 01:00:01 invisiblethings CRON[2985]: pam_unix(cron:session): session closed for user smmsp
Mar 14 01:00:02 invisiblethings CRON[2986]: pam_unix(cron:session): session closed for user root
Mar 14 01:01:01 invisiblethings polkit-agent-helper-1[8312]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:01:01 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.95 [/usr/bin/python /usr/bin/software-center apt://encfs] (owned by unix-user:adminroot)
Mar 14 01:01:30 invisiblethings su[11492]: Successful su for www-data by root
Mar 14 01:01:30 invisiblethings su[11492]: + ??? root:www-data
Mar 14 01:01:30 invisiblethings su[11492]: pam_unix(su:session): session opened for user www-data by (uid=0)
Mar 14 01:01:30 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user www-data by (uid=0)
Mar 14 01:01:30 invisiblethings systemd-logind[727]: New session c3 of user www-data.
Mar 14 01:01:30 invisiblethings su[11492]: pam_unix(su:session): session closed for user www-data
Mar 14 01:01:31 invisiblethings systemd-logind[727]: Removed session c3.
Mar 14 01:01:32 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:01:32 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:01:32 invisiblethings pkexec[11549]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:03:27 invisiblethings polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.pkexec.synaptic for unix-process:21004:117756 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:adminroot)
Mar 14 01:03:27 invisiblethings pkexec[21008]: adminroot: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/sbin/synaptic]
Mar 14 01:04:25 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:04:25 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:04:25 invisiblethings pkexec[26726]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:05:00 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:31600:127234 (system bus name :1.116 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:00 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:31600:127234 (system bus name :1.116, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:02 invisiblethings groupadd[31826]: group added to /etc/group: name=clamav, GID=133
Mar 14 01:05:02 invisiblethings groupadd[31826]: group added to /etc/gshadow: name=clamav
Mar 14 01:05:02 invisiblethings groupadd[31826]: new group: name=clamav, GID=133
Mar 14 01:05:03 invisiblethings useradd[31847]: new user: name=clamav, UID=123, GID=133, home=/var/lib/clamav, shell=/bin/false
Mar 14 01:05:03 invisiblethings chage[31902]: changed password expiry for clamav
Mar 14 01:05:03 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:31944:127580 (system bus name :1.117 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:03 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:31944:127580 (system bus name :1.117, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:11 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:32733:128353 (system bus name :1.118 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:11 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:32733:128353 (system bus name :1.118, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:51 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:4350:132418 (system bus name :1.119 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:52 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:4350:132418 (system bus name :1.119, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:55 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:5546:132804 (system bus name :1.120 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:55 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:5546:132804 (system bus name :1.120, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:5582:132830 (system bus name :1.121 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:5582:132830 (system bus name :1.121, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:5643:132865 (system bus name :1.122 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:5643:132865 (system bus name :1.122, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:5673:132887 (system bus name :1.123 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:05:56 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:5673:132887 (system bus name :1.123, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:06:12 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-process:7584:134486 (system bus name :1.124 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 01:06:12 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-process:7584:134486 (system bus name :1.124, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:06:35 invisiblethings polkit-agent-helper-1[9188]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:06:35 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.95 [/usr/bin/python /usr/bin/software-center apt://encfs] (owned by unix-user:adminroot)
Mar 14 01:06:38 invisiblethings su[9994]: Successful su for adminroot by root
Mar 14 01:06:38 invisiblethings su[9994]: + ??? root:adminroot
Mar 14 01:06:38 invisiblethings su[9994]: pam_unix(su:session): session opened for user adminroot by (uid=0)
Mar 14 01:06:38 invisiblethings su[9994]: pam_systemd(su:session): Cannot create session: Already running in a session
Mar 14 01:06:38 invisiblethings su[9994]: pam_unix(su:session): session closed for user adminroot
Mar 14 01:07:25 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:07:25 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:07:25 invisiblethings pkexec[15131]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:10:25 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:10:25 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:10:25 invisiblethings pkexec[1154]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:17:01 invisiblethings CRON[10817]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 14 01:17:01 invisiblethings CRON[10817]: pam_unix(cron:session): session closed for user root
Mar 14 01:17:03 invisiblethings polkit-agent-helper-1[10463]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:17:03 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action com.ubuntu.systemservice.setproxy for system-bus-name::1.100 [unity-control-center] (owned by unix-user:adminroot)
Mar 14 01:20:01 invisiblethings CRON[29148]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 14 01:20:01 invisiblethings CRON[29148]: pam_unix(cron:session): session closed for user smmsp
Mar 14 01:23:07 invisiblethings polkit-agent-helper-1[16196]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:23:07 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:16186:235383 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:adminroot)
Mar 14 01:23:07 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:23:07 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:23:07 invisiblethings pkexec[16189]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/sbin/synaptic]
Mar 14 01:26:25 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/home/adminroot/Musik/buck-security-master/buck-security
Mar 14 01:26:25 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:26:25 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:28:02 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot/Musik/buck-security-master ; USER=root ; COMMAND=./buck-security
Mar 14 01:28:02 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:28:02 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:29:58 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot/Musik/buck-security-master ; USER=root ; COMMAND=./buck-security --make-checksums
Mar 14 01:29:58 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:29:58 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:30:34 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot/Musik/buck-security-master ; USER=root ; COMMAND=./buck-security --output=3
Mar 14 01:30:34 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:30:34 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:30:47 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot/Musik/buck-security-master ; USER=root ; COMMAND=./buck-security
Mar 14 01:30:47 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:30:48 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:31:45 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot/Musik/buck-security-master ; USER=root ; COMMAND=/usr/bin/apt-get install chkrootkit
Mar 14 01:31:45 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:31:45 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:32:01 invisiblethings sudo: pam_unix(sudo:auth): authentication failure; logname=adminroot uid=1000 euid=0 tty=/dev/pts/1 ruser=adminroot rhost=  user=adminroot
Mar 14 01:32:07 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install chkrootkit
Mar 14 01:32:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:32:08 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:32:17 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/chkrootkit
Mar 14 01:32:17 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:32:22 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:33:18 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install rkhunter
Mar 14 01:33:18 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:34:04 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:34:07 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/rkhunter --update
Mar 14 01:34:07 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:34:11 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:34:24 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/rkhunter --propupd --update
Mar 14 01:34:24 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:34:25 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:34:25 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:34:25 invisiblethings pkexec[14537]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:34:34 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:35:03 invisiblethings sudo: adminroot : TTY=pts/1 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/rkhunter -c --display-logfile
Mar 14 01:35:03 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:35:04 invisiblethings Rootkit Hunter: Rootkit hunter check started (version 1.4.2)
Mar 14 01:36:04 invisiblethings sudo: adminroot : TTY=pts/3 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install lynis
Mar 14 01:36:04 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:36:05 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:36:20 invisiblethings Rootkit Hunter: Scanning took 1 minute and 16 seconds
Mar 14 01:36:20 invisiblethings Rootkit Hunter: Please inspect this machine, because it may be infected.
Mar 14 01:36:20 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:36:22 invisiblethings sudo: adminroot : TTY=pts/3 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/apt-get install manpages-de
Mar 14 01:36:22 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:36:30 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:37:20 invisiblethings sudo: adminroot : TTY=pts/3 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/lynis
Mar 14 01:37:20 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:37:20 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:37:25 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:37:25 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:37:25 invisiblethings pkexec[28240]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:38:23 invisiblethings sudo: adminroot : TTY=pts/3 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/sbin/lynis audit system
Mar 14 01:38:23 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)
Mar 14 01:40:01 invisiblethings CRON[10162]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 14 01:40:01 invisiblethings CRON[10162]: pam_unix(cron:session): session closed for user smmsp
Mar 14 01:41:18 invisiblethings sudo: pam_unix(sudo:session): session closed for user root
Mar 14 01:41:55 invisiblethings polkit-agent-helper-1[27748]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:41:55 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.173 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:adminroot)
Mar 14 01:43:13 invisiblethings polkit-agent-helper-1[3765]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:43:13 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:3755:355625 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:adminroot)
Mar 14 01:43:13 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:43:13 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:43:13 invisiblethings pkexec[3759]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/sbin/synaptic]
Mar 14 01:43:27 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:43:27 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:43:27 invisiblethings pkexec[5886]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:49:22 invisiblethings polkit-agent-helper-1[18396]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 01:49:22 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.canonical.xdiagnose.pkexec for unix-process:1262:8933 [/sbin/upstart --user] (owned by unix-user:adminroot)
Mar 14 01:49:22 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:49:22 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:49:22 invisiblethings pkexec[18381]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/xdiagnose]
Mar 14 01:49:31 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 01:49:31 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 01:49:31 invisiblethings pkexec[19463]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 14 01:49:59 invisiblethings dbus[741]: [system] Rejected send message, 2 matched rules; type="method_call", sender=":1.188" (uid=1000 pid=20636 comm="systemadm ") interface="org.freedesktop.systemd1.Manager" member="CreateSnapshot" error name="(unset)" requested_reply="0" destination="org.freedesktop.systemd1" (uid=0 pid=1 comm="/sbin/init splash ")
Mar 14 01:56:05 invisiblethings systemd-logind[727]: Power key pressed.
Mar 14 01:56:13 invisiblethings polkitd(authority=local): Unregistered Authentication Agent for unix-session:c2 (system bus name :1.60, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 14 01:56:13 invisiblethings systemd-logind[727]: System is powering down.
Mar 14 10:22:02 invisiblethings systemd-logind[1472]: New seat seat0.
Mar 14 10:22:02 invisiblethings systemd-logind[1472]: Watching system buttons on /dev/input/event2 (Power Button)
Mar 14 10:22:02 invisiblethings systemd-logind[1472]: Watching system buttons on /dev/input/event3 (Video Bus)
Mar 14 10:22:02 invisiblethings systemd-logind[1472]: Watching system buttons on /dev/input/event0 (Power Button)
Mar 14 10:22:02 invisiblethings systemd-logind[1472]: Watching system buttons on /dev/input/event1 (Sleep Button)
Mar 14 10:22:12 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 14 10:22:12 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 14 10:22:12 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 14 10:22:12 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 14 10:22:12 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Mar 14 10:22:12 invisiblethings systemd-logind[1472]: New session c1 of user lightdm.
Mar 14 10:22:12 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Mar 14 10:22:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Mar 14 10:22:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet.so
Mar 14 10:22:17 invisiblethings lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Mar 14 10:22:17 invisiblethings lightdm: PAM adding faulty module: pam_kwallet5.so
Mar 14 10:22:17 invisiblethings lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "adminroot"
Mar 14 10:22:26 invisiblethings lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Mar 14 10:22:26 invisiblethings lightdm: pam_unix(lightdm:session): session opened for user adminroot by (uid=0)
Mar 14 10:22:26 invisiblethings systemd: pam_unix(systemd-user:session): session opened for user adminroot by (uid=0)
Mar 14 10:22:27 invisiblethings systemd-logind[1472]: New session c2 of user adminroot.
Mar 14 10:22:35 invisiblethings gnome-keyring-daemon[2005]: The PKCS#11 component was already initialized
Mar 14 10:22:36 invisiblethings gnome-keyring-daemon[2005]: The SSH agent was already initialized
Mar 14 10:22:36 invisiblethings gnome-keyring-daemon[2005]: The Secret Service was already initialized
Mar 14 10:22:38 invisiblethings polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.60 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 14 10:22:43 invisiblethings dbus[1488]: [system] Failed to activate service 'org.bluez': timed out
Mar 14 10:22:46 invisiblethings dbus[1488]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2514 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.4" (uid=0 pid=1482 comm="/usr/sbin/NetworkManager --no-daemon ")
Mar 14 10:23:13 invisiblethings polkit-agent-helper-1[2484]: pam_ecryptfs: pam_sm_authenticate: /home/adminroot is already mounted
Mar 14 10:23:13 invisiblethings polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:adminroot to gain ONE-SHOT authorization for action com.ubuntu.pkexec.gufw for unix-process:2343:12634 [/bin/sh /usr/bin/gufw] (owned by unix-user:adminroot)
Mar 14 10:23:13 invisiblethings pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 14 10:23:13 invisiblethings pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 14 10:23:13 invisiblethings pkexec[2355]: adminroot: Executing command [USER=root] [TTY=unknown] [CWD=/home/adminroot] [COMMAND=/usr/bin/gufw-pkexec adminroot]
Mar 14 10:24:12 invisiblethings systemd-logind[1472]: Removed session c1.
Mar 14 10:24:12 invisiblethings systemd: pam_unix(systemd-user:session): session closed for user lightdm
Mar 14 10:26:35 invisiblethings sudo: adminroot : TTY=pts/6 ; PWD=/home/adminroot ; USER=root ; COMMAND=/usr/bin/nautilus
Mar 14 10:26:35 invisiblethings sudo: pam_unix(sudo:session): session opened for user root by adminroot(uid=0)


dennissteins 14.03.2016 11:04

Kern.log Teil 1 (den UFW Teil habe ich raus gelassen)


Code:

Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuset
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpu
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuacct
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Linux version 4.2.0-16-generic (buildd@lcy01-07) (gcc version 5.2.1 20151003 (Ubuntu 5.2.1-21ubuntu2) ) #19-Ubuntu SMP Thu Oct 8 15:35:06 UTC 2015 (Ubuntu 4.2.0-16.19-generic 4.2.3)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.2.0-16-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] KERNEL supported cpus:
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  Intel GenuineIntel
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  AMD AuthenticAMD
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  Centaur CentaurHauls
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x01: 'x87 floating point registers'
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x02: 'SSE registers'
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] x86/fpu: Enabled xstate features 0x3, context size is 0x240 bytes, using 'standard' format.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] x86/fpu: Using 'eager' FPU context switches.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: BIOS-provided physical RAM map:
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009d7ff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x000000000009d800-0x000000000009ffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000c8b3bfff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b3c000-0x00000000c8b42fff] ACPI NVS
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b43000-0x00000000c9601fff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c9602000-0x00000000c98c2fff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c98c3000-0x00000000dbaf6fff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbaf7000-0x00000000dbb5ffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb60000-0x00000000dbb89fff] ACPI data
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb8a000-0x00000000dbceffff] ACPI NVS
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbcf0000-0x00000000dbffefff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbfff000-0x00000000dbffffff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dd000000-0x00000000df1fffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000f8000000-0x00000000fbffffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed00000-0x00000000fed03fff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed1c000-0x00000000fed1ffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000ff000000-0x00000000ffffffff] reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fdfffff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] NX (Execute Disable) protection: active
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] SMBIOS 2.8 present.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] DMI: Hewlett-Packard HP 280 G1 MT/2B34, BIOS 80.14 09/28/2015
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: last_pfn = 0x11fe00 max_arch_pfn = 0x400000000
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] MTRR default type: uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] MTRR fixed ranges enabled:
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  00000-9FFFF write-back
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  A0000-BFFFF uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  C0000-CFFFF write-protect
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  D0000-E7FFF uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  E8000-FFFFF write-protect
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] MTRR variable ranges enabled:
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  0 base 0000000000 mask 7F00000000 write-back
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  1 base 0100000000 mask 7FE0000000 write-back
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  2 base 00E0000000 mask 7FE0000000 uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  3 base 00DE000000 mask 7FFE000000 uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  4 base 00DD000000 mask 7FFF000000 uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  5 base 011FE00000 mask 7FFFE00000 uncachable
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  6 disabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  7 disabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  8 disabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  9 disabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] x86/PAT: Configuration [0-7]: WB  WC  UC- UC  WB  WC  UC- WT 
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] original variable MTRRs
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 4GB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 1, base: 4GB, range: 512MB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 2, base: 3584MB, range: 512MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 3, base: 3552MB, range: 32MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 4, base: 3536MB, range: 16MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 5, base: 4606MB, range: 2MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] total RAM covered: 4046M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Found optimal setting for mtrr clean up
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  gran_size: 64K        chunk_size: 64M        num_reg: 7          lose cover RAM: 0G
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] New variable MTRRs
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 2GB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 1, base: 2GB, range: 1GB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 2, base: 3GB, range: 512MB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 3, base: 3536MB, range: 16MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 4, base: 3552MB, range: 32MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 5, base: 4GB, range: 512MB, type WB
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] reg 6, base: 4606MB, range: 2MB, type UC
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: update [mem 0xdd000000-0xffffffff] usable ==> reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: last_pfn = 0xdc000 max_arch_pfn = 0x400000000
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] found SMP MP-table at [mem 0x000fd7c0-0x000fd7cf] mapped at [ffff8800000fd7c0]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Scanning 1 areas for low memory corruption
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Base memory trampoline at [ffff880000097000] 97000 size 24576
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Using GB pages for direct mapping
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x00000000-0x000fffff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff0000, 0x01ff0fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff1000, 0x01ff1fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff2000, 0x01ff2fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x11fc00000-0x11fdfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x11fc00000-0x11fdfffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff3000, 0x01ff3fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x100000000-0x11fbfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x100000000-0x11fbfffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc0000000-0xc8b3bfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc0000000-0xc89fffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc8a00000-0xc8b3bfff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff4000, 0x01ff4fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] BRK [0x01ff5000, 0x01ff5fff] PGTABLE
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc8b43000-0xc9601fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc8b43000-0xc8bfffff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc8c00000-0xc95fffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc9600000-0xc9601fff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc98c3000-0xdbaf6fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc98c3000-0xc99fffff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xc9a00000-0xdb9fffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xdba00000-0xdbaf6fff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xdbfff000-0xdbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0xdbfff000-0xdbffffff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00100000-0xbfffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x00100000-0x001fffff] page 4k
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x00200000-0x3fffffff] page 2M
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [mem 0x40000000-0xbfffffff] page 1G
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] RAMDISK: [mem 0x33ba6000-0x35dcafff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: Early table checksum verification disabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: RSDP 0x00000000000F0490 000024 (v02 HPQOEM)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: XSDT 0x00000000DBB69088 000094 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: FACP 0x00000000DBB81FA0 00010C (v05 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: DSDT 0x00000000DBB691B0 018DEC (v02 HPQOEM SLIC-CPC 00008014 INTL 20120711)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: FACS 0x00000000DBCEFF80 000040
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: APIC 0x00000000DBB820B0 000062 (v03 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: FPDT 0x00000000DBB82118 000044 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: FIDT 0x00000000DBB82160 00009C (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: TCPA 0x00000000DBB82200 000032 (v02 HPQOEM SLIC-CPC 00000001 MSFT 01000013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82238 000C7D (v02 HPQOEM SLIC-CPC 00001000 INTL 20120711)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82EB8 000539 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB833F8 000B74 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: MCFG 0x00000000DBB83F70 00003C (v01 HPQOEM SLIC-CPC 01072009 MSFT 00000097)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: HPET 0x00000000DBB83FB0 000038 (v01 HPQOEM SLIC-CPC 01072009 AMI. 00000005)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB83FE8 00036D (v01 HPQOEM SLIC-CPC 00001000 INTL 20120711)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB84358 005722 (v02 HPQOEM SLIC-CPC 00003000 INTL 20120711)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: UEFI 0x00000000DBB89A80 000042 (v01 HPQOEM SLIC-CPC 01072009      00000000)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: DBGP 0x00000000DBB89AC8 000034 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: Local APIC address 0xfee00000
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] No NUMA configuration found
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Faking a node at [mem 0x0000000000000000-0x000000011fdfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] NODE_DATA(0) allocated [mem 0x11fdf7000-0x11fdfbfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  [ffffea0000000000-ffffea00047fffff] PMD -> [ffff88011b400000-ffff88011f3fffff] on node 0
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Zone ranges:
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA      [mem 0x0000000000001000-0x0000000000ffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA32    [mem 0x0000000001000000-0x00000000ffffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  Normal  [mem 0x0000000100000000-0x000000011fdfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Movable zone start for each node
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Early memory node ranges
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000000001000-0x000000000009cfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000000100000-0x00000000c8b3bfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000c8b43000-0x00000000c9601fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000c98c3000-0x00000000dbaf6fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000dbfff000-0x00000000dbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000100000000-0x000000011fdfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Initmem setup node 0 [mem 0x0000000000001000-0x000000011fdfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] On node 0 totalpages: 1029580
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA zone: 64 pages used for memmap
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA zone: 21 pages reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA zone: 3996 pages, LIFO batch:0
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA32 zone: 13985 pages used for memmap
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  DMA32 zone: 895024 pages, LIFO batch:31
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  Normal zone: 2040 pages used for memmap
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]  Normal zone: 130560 pages, LIFO batch:31
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Reserving Intel graphics stolen memory at 0xdd200000-0xdf1fffff
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: PM-Timer IO Port: 0x1808
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: Local APIC address 0xfee00000
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] high edge lint[0x1])
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] IOAPIC[0]: apic_id 8, version 32, address 0xfec00000, GSI 0-23
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: IRQ0 used by override.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: IRQ9 used by override.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Using ACPI (MADT) for SMP configuration information
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] ACPI: HPET id: 0x8086a701 base: 0xfed00000
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] smpboot: Allowing 2 CPUs, 0 hotplug CPUs
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x00000000-0x00000fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x0009d000-0x0009dfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x0009e000-0x0009ffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x000a0000-0x000dffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x000e0000-0x000fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xc8b3c000-0xc8b42fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xc9602000-0xc98c2fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbaf7000-0xdbb5ffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbb60000-0xdbb89fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbb8a000-0xdbceffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbcf0000-0xdbffefff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdc000000-0xdcffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdd000000-0xdf1fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdf200000-0xf7ffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xf8000000-0xfbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfc000000-0xfebfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfec00000-0xfec00fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfec01000-0xfecfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed00000-0xfed03fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed04000-0xfed1bfff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed1c000-0xfed1ffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed20000-0xfedfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfee00000-0xfee00fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfee01000-0xfeffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xff000000-0xffffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] e820: [mem 0xdf200000-0xf7ffffff] available for PCI devices
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Booting paravirtualized kernel on bare hardware
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645519600211568 ns
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] setup_percpu: NR_CPUS:256 nr_cpumask_bits:256 nr_cpu_ids:2 nr_node_ids:1
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PERCPU: Embedded 33 pages/cpu @ffff88011fa00000 s96728 r8192 d30248 u1048576
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] pcpu-alloc: s96728 r8192 d30248 u1048576 alloc=1*2097152
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] pcpu-alloc: [0] 0 1
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages: 1013470
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Policy zone: Normal
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Kernel command line: BOOT_IMAGE=/vmlinuz-4.2.0-16-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Calgary: detecting Calgary via BIOS EBDA area
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Calgary: Unable to locate Rio Grande table in EBDA - bailing!
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Memory: 3934788K/4118320K available (8146K kernel code, 1237K rwdata, 3800K rodata, 1460K init, 1292K bss, 183532K reserved, 0K cma-reserved)
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Hierarchical RCU implementation.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]        Build-time adjustment of leaf fanout to 64.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]        RCU restricting CPUs from NR_CPUS=256 to nr_cpu_ids=2.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] RCU: Adjusting geometry for rcu_fanout_leaf=64, nr_cpu_ids=2
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] NR_IRQS:16640 nr_irqs:440 16
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]        Offload RCU callbacks from all CPUs
Mar 13 02:14:35 invisiblethings kernel: [    0.000000]        Offload RCU callbacks from CPUs: 0-1.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] spurious 8259A interrupt: IRQ7.
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] vt handoff: transparent VT on vt#7
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] Console: colour dummy device 80x25
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] console [tty0] enabled
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 133484882848 ns
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] hpet clockevent registered
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] tsc: Fast TSC calibration using PIT
Mar 13 02:14:35 invisiblethings kernel: [    0.000000] tsc: Detected 3192.678 MHz processor
Mar 13 02:14:35 invisiblethings kernel: [    0.000022] Calibrating delay loop (skipped), value calculated using timer frequency.. 6385.35 BogoMIPS (lpj=12770712)
Mar 13 02:14:35 invisiblethings kernel: [    0.000024] pid_max: default: 32768 minimum: 301
Mar 13 02:14:35 invisiblethings kernel: [    0.000028] ACPI: Core revision 20150619
Mar 13 02:14:35 invisiblethings kernel: [    0.014999] ACPI: All ACPI Tables successfully acquired
Mar 13 02:14:35 invisiblethings kernel: [    0.015014] Security Framework initialized
Mar 13 02:14:35 invisiblethings kernel: [    0.015022] AppArmor: AppArmor initialized
Mar 13 02:14:35 invisiblethings kernel: [    0.015023] Yama: becoming mindful.
Mar 13 02:14:35 invisiblethings kernel: [    0.015223] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.016258] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.016782] Mount-cache hash table entries: 8192 (order: 4, 65536 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.016787] Mountpoint-cache hash table entries: 8192 (order: 4, 65536 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.016970] Initializing cgroup subsys blkio
Mar 13 02:14:35 invisiblethings kernel: [    0.016973] Initializing cgroup subsys memory
Mar 13 02:14:35 invisiblethings kernel: [    0.016978] Initializing cgroup subsys devices
Mar 13 02:14:35 invisiblethings kernel: [    0.016980] Initializing cgroup subsys freezer
Mar 13 02:14:35 invisiblethings kernel: [    0.016981] Initializing cgroup subsys net_cls
Mar 13 02:14:35 invisiblethings kernel: [    0.016983] Initializing cgroup subsys perf_event
Mar 13 02:14:35 invisiblethings kernel: [    0.016984] Initializing cgroup subsys net_prio
Mar 13 02:14:35 invisiblethings kernel: [    0.016986] Initializing cgroup subsys hugetlb
Mar 13 02:14:35 invisiblethings kernel: [    0.017005] CPU: Physical Processor ID: 0
Mar 13 02:14:35 invisiblethings kernel: [    0.017005] CPU: Processor Core ID: 0
Mar 13 02:14:35 invisiblethings kernel: [    0.017009] ENERGY_PERF_BIAS: Set to 'normal', was 'performance'
Mar 13 02:14:35 invisiblethings kernel: [    0.017009] ENERGY_PERF_BIAS: View and update with x86_energy_perf_policy(8)
Mar 13 02:14:35 invisiblethings kernel: [    0.017766] mce: CPU supports 7 MCE banks
Mar 13 02:14:35 invisiblethings kernel: [    0.017776] CPU0: Thermal monitoring enabled (TM1)
Mar 13 02:14:35 invisiblethings kernel: [    0.017783] process: using mwait in idle threads
Mar 13 02:14:35 invisiblethings kernel: [    0.017785] Last level iTLB entries: 4KB 1024, 2MB 1024, 4MB 1024
Mar 13 02:14:35 invisiblethings kernel: [    0.017786] Last level dTLB entries: 4KB 1024, 2MB 1024, 4MB 1024, 1GB 4
Mar 13 02:14:35 invisiblethings kernel: [    0.017883] Freeing SMP alternatives memory: 28K (ffffffff81ea4000 - ffffffff81eab000)
Mar 13 02:14:35 invisiblethings kernel: [    0.019362] ftrace: allocating 30905 entries in 121 pages
Mar 13 02:14:35 invisiblethings kernel: [    0.029851] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=0 pin2=0
Mar 13 02:14:35 invisiblethings kernel: [    0.069572] TSC deadline timer enabled
Mar 13 02:14:35 invisiblethings kernel: [    0.069575] smpboot: CPU0: Intel(R) Pentium(R) CPU G3250 @ 3.20GHz (fam: 06, model: 3c, stepping: 03)
Mar 13 02:14:35 invisiblethings kernel: [    0.069596] Performance Events: PEBS fmt2+, 16-deep LBR, Haswell events, full-width counters, Intel PMU driver.
Mar 13 02:14:35 invisiblethings kernel: [    0.069612] ... version:                3
Mar 13 02:14:35 invisiblethings kernel: [    0.069613] ... bit width:              48
Mar 13 02:14:35 invisiblethings kernel: [    0.069613] ... generic registers:      8
Mar 13 02:14:35 invisiblethings kernel: [    0.069614] ... value mask:            0000ffffffffffff
Mar 13 02:14:35 invisiblethings kernel: [    0.069615] ... max period:            0000ffffffffffff
Mar 13 02:14:35 invisiblethings kernel: [    0.069615] ... fixed-purpose events:  3
Mar 13 02:14:35 invisiblethings kernel: [    0.069616] ... event mask:            00000007000000ff
Mar 13 02:14:35 invisiblethings kernel: [    0.070200] x86: Booting SMP configuration:
Mar 13 02:14:35 invisiblethings kernel: [    0.070201] .... node  #0, CPUs:      #1
Mar 13 02:14:35 invisiblethings kernel: [    0.074235] x86: Booted up 1 node, 2 CPUs
Mar 13 02:14:35 invisiblethings kernel: [    0.074238] smpboot: Total of 2 processors activated (12770.71 BogoMIPS)
Mar 13 02:14:35 invisiblethings kernel: [    0.074264] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
Mar 13 02:14:35 invisiblethings kernel: [    0.075627] devtmpfs: initialized
Mar 13 02:14:35 invisiblethings kernel: [    0.076962] evm: security.selinux
Mar 13 02:14:35 invisiblethings kernel: [    0.076963] evm: security.SMACK64
Mar 13 02:14:35 invisiblethings kernel: [    0.076963] evm: security.SMACK64EXEC
Mar 13 02:14:35 invisiblethings kernel: [    0.076964] evm: security.SMACK64TRANSMUTE
Mar 13 02:14:35 invisiblethings kernel: [    0.076964] evm: security.SMACK64MMAP
Mar 13 02:14:35 invisiblethings kernel: [    0.076965] evm: security.ima
Mar 13 02:14:35 invisiblethings kernel: [    0.076965] evm: security.capability
Mar 13 02:14:35 invisiblethings kernel: [    0.077004] PM: Registering ACPI NVS region [mem 0xc8b3c000-0xc8b42fff] (28672 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.077005] PM: Registering ACPI NVS region [mem 0xdbb8a000-0xdbceffff] (1466368 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.077064] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
Mar 13 02:14:35 invisiblethings kernel: [    0.077115] pinctrl core: initialized pinctrl subsystem
Mar 13 02:14:35 invisiblethings kernel: [    0.077199] RTC time:  1:13:57, date: 03/13/16
Mar 13 02:14:35 invisiblethings kernel: [    0.077279] NET: Registered protocol family 16
Mar 13 02:14:35 invisiblethings kernel: [    0.086260] cpuidle: using governor ladder
Mar 13 02:14:35 invisiblethings kernel: [    0.094271] cpuidle: using governor menu
Mar 13 02:14:35 invisiblethings kernel: [    0.094316] ACPI FADT declares the system doesn't support PCIe ASPM, so disable it
Mar 13 02:14:35 invisiblethings kernel: [    0.094317] ACPI: bus type PCI registered
Mar 13 02:14:35 invisiblethings kernel: [    0.094318] acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5
Mar 13 02:14:35 invisiblethings kernel: [    0.094362] PCI: MMCONFIG for domain 0000 [bus 00-3f] at [mem 0xf8000000-0xfbffffff] (base 0xf8000000)
Mar 13 02:14:35 invisiblethings kernel: [    0.094363] PCI: MMCONFIG at [mem 0xf8000000-0xfbffffff] reserved in E820
Mar 13 02:14:35 invisiblethings kernel: [    0.094370] PCI: Using configuration type 1 for base access
Mar 13 02:14:35 invisiblethings kernel: [    0.094502] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
Mar 13 02:14:35 invisiblethings kernel: [    0.094509] perf_event_intel: PMU erratum BJ122, BV98, HSD29 workaround disabled, HT off
Mar 13 02:14:35 invisiblethings kernel: [    0.102497] ACPI: Added _OSI(Module Device)
Mar 13 02:14:35 invisiblethings kernel: [    0.102498] ACPI: Added _OSI(Processor Device)
Mar 13 02:14:35 invisiblethings kernel: [    0.102499] ACPI: Added _OSI(3.0 _SCP Extensions)
Mar 13 02:14:35 invisiblethings kernel: [    0.102500] ACPI: Added _OSI(Processor Aggregator Device)
Mar 13 02:14:35 invisiblethings kernel: [    0.105968] ACPI: Executed 6 blocks of module-level executable AML code
Mar 13 02:14:35 invisiblethings kernel: [    0.110077] ACPI: Dynamic OEM Table Load:
Mar 13 02:14:35 invisiblethings kernel: [    0.110082] ACPI: SSDT 0xFFFF88011A5B5400 0003D3 (v02 HPQOEM SLIC-CPC 00003001 INTL 20051117)
Mar 13 02:14:35 invisiblethings kernel: [    0.110640] ACPI: Dynamic OEM Table Load:
Mar 13 02:14:35 invisiblethings kernel: [    0.110644] ACPI: SSDT 0xFFFF88011B016800 0005AA (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 02:14:35 invisiblethings kernel: [    0.111233] ACPI: Dynamic OEM Table Load:
Mar 13 02:14:35 invisiblethings kernel: [    0.111236] ACPI: SSDT 0xFFFF88011A5D7000 000119 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 02:14:35 invisiblethings kernel: [    0.111872] ACPI: Interpreter enabled
Mar 13 02:14:35 invisiblethings kernel: [    0.111879] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S1_] (20150619/hwxface-580)
Mar 13 02:14:35 invisiblethings kernel: [    0.111885] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S2_] (20150619/hwxface-580)
Mar 13 02:14:35 invisiblethings kernel: [    0.111903] ACPI: (supports S0 S3 S4 S5)
Mar 13 02:14:35 invisiblethings kernel: [    0.111904] ACPI: Using IOAPIC for interrupt routing
Mar 13 02:14:35 invisiblethings kernel: [    0.111926] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
Mar 13 02:14:35 invisiblethings kernel: [    0.112275] ACPI: Power Resource [PG00] (on)
Mar 13 02:14:35 invisiblethings kernel: [    0.112487] ACPI: Power Resource [PG01] (on)
Mar 13 02:14:35 invisiblethings kernel: [    0.112695] ACPI: Power Resource [PG02] (on)
Mar 13 02:14:35 invisiblethings kernel: [    0.115226] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.115415] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.115605] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.115809] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.115992] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.116179] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.116364] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.116549] ACPI: Power Resource [WRST] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.118834] ACPI: Power Resource [FN00] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.118890] ACPI: Power Resource [FN01] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.118943] ACPI: Power Resource [FN02] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.118998] ACPI: Power Resource [FN03] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.119052] ACPI: Power Resource [FN04] (off)
Mar 13 02:14:35 invisiblethings kernel: [    0.119678] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-3e])
Mar 13 02:14:35 invisiblethings kernel: [    0.119683] acpi PNP0A08:00: _OSC: OS supports [ExtendedConfig ASPM ClockPM Segments MSI]
Mar 13 02:14:35 invisiblethings kernel: [    0.120179] acpi PNP0A08:00: _OSC: OS now controls [PCIeHotplug PME AER PCIeCapability]
Mar 13 02:14:35 invisiblethings kernel: [    0.120180] acpi PNP0A08:00: FADT indicates ASPM is unsupported, using BIOS configuration
Mar 13 02:14:35 invisiblethings kernel: [    0.120339] acpi PNP0A08:00: host bridge window expanded to [mem 0xdf200000-0xfeafffff window]; [mem 0xfe101000-0xfe113fff window] ignored
Mar 13 02:14:35 invisiblethings kernel: [    0.120475] PCI host bridge to bus 0000:00
Mar 13 02:14:35 invisiblethings kernel: [    0.120477] pci_bus 0000:00: root bus resource [bus 00-3e]
Mar 13 02:14:35 invisiblethings kernel: [    0.120479] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7 window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120480] pci_bus 0000:00: root bus resource [io  0x0d00-0xffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120481] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120483] pci_bus 0000:00: root bus resource [mem 0x000d0000-0x000d3fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120484] pci_bus 0000:00: root bus resource [mem 0x000d4000-0x000d7fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120485] pci_bus 0000:00: root bus resource [mem 0x000d8000-0x000dbfff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120486] pci_bus 0000:00: root bus resource [mem 0x000dc000-0x000dffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120487] pci_bus 0000:00: root bus resource [mem 0x000e0000-0x000e3fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120489] pci_bus 0000:00: root bus resource [mem 0x000e4000-0x000e7fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120490] pci_bus 0000:00: root bus resource [mem 0xdf200000-0xfeafffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.120495] pci 0000:00:00.0: [8086:0c00] type 00 class 0x060000
Mar 13 02:14:35 invisiblethings kernel: [    0.120558] pci 0000:00:01.0: [8086:0c01] type 01 class 0x060400
Mar 13 02:14:35 invisiblethings kernel: [    0.120582] pci 0000:00:01.0: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.120633] pci 0000:00:01.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.120663] pci 0000:00:02.0: [8086:0402] type 00 class 0x030000
Mar 13 02:14:35 invisiblethings kernel: [    0.120673] pci 0000:00:02.0: reg 0x10: [mem 0xf7800000-0xf7bfffff 64bit]
Mar 13 02:14:35 invisiblethings kernel: [    0.120678] pci 0000:00:02.0: reg 0x18: [mem 0xe0000000-0xefffffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.120681] pci 0000:00:02.0: reg 0x20: [io  0xf000-0xf03f]
Mar 13 02:14:35 invisiblethings kernel: [    0.120767] pci 0000:00:14.0: [8086:8c31] type 00 class 0x0c0330
Mar 13 02:14:35 invisiblethings kernel: [    0.120791] pci 0000:00:14.0: reg 0x10: [mem 0xf7d00000-0xf7d0ffff 64bit]
Mar 13 02:14:35 invisiblethings kernel: [    0.120834] pci 0000:00:14.0: PME# supported from D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.120867] pci 0000:00:14.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.120896] pci 0000:00:16.0: [8086:8c3a] type 00 class 0x078000
Mar 13 02:14:35 invisiblethings kernel: [    0.120920] pci 0000:00:16.0: reg 0x10: [mem 0xf7d15000-0xf7d1500f 64bit]
Mar 13 02:14:35 invisiblethings kernel: [    0.120966] pci 0000:00:16.0: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.121045] pci 0000:00:1a.0: [8086:8c2d] type 00 class 0x0c0320
Mar 13 02:14:35 invisiblethings kernel: [    0.121070] pci 0000:00:1a.0: reg 0x10: [mem 0xf7d13000-0xf7d133ff]
Mar 13 02:14:35 invisiblethings kernel: [    0.121131] pci 0000:00:1a.0: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.121165] pci 0000:00:1a.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.121194] pci 0000:00:1c.0: [8086:8c10] type 01 class 0x060400
Mar 13 02:14:35 invisiblethings kernel: [    0.121246] pci 0000:00:1c.0: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.121305] pci 0000:00:1c.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.121334] pci 0000:00:1c.3: [8086:8c16] type 01 class 0x060400
Mar 13 02:14:35 invisiblethings kernel: [    0.121388] pci 0000:00:1c.3: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.121445] pci 0000:00:1c.3: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.121478] pci 0000:00:1d.0: [8086:8c26] type 00 class 0x0c0320
Mar 13 02:14:35 invisiblethings kernel: [    0.121503] pci 0000:00:1d.0: reg 0x10: [mem 0xf7d12000-0xf7d123ff]
Mar 13 02:14:35 invisiblethings kernel: [    0.121563] pci 0000:00:1d.0: PME# supported from D0 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.121597] pci 0000:00:1d.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.121626] pci 0000:00:1f.0: [8086:8c5c] type 00 class 0x060100
Mar 13 02:14:35 invisiblethings kernel: [    0.121760] pci 0000:00:1f.2: [8086:8c02] type 00 class 0x010601
Mar 13 02:14:35 invisiblethings kernel: [    0.121778] pci 0000:00:1f.2: reg 0x10: [io  0xf0b0-0xf0b7]
Mar 13 02:14:35 invisiblethings kernel: [    0.121785] pci 0000:00:1f.2: reg 0x14: [io  0xf0a0-0xf0a3]
Mar 13 02:14:35 invisiblethings kernel: [    0.121792] pci 0000:00:1f.2: reg 0x18: [io  0xf090-0xf097]
Mar 13 02:14:35 invisiblethings kernel: [    0.121799] pci 0000:00:1f.2: reg 0x1c: [io  0xf080-0xf083]
Mar 13 02:14:35 invisiblethings kernel: [    0.121805] pci 0000:00:1f.2: reg 0x20: [io  0xf060-0xf07f]
Mar 13 02:14:35 invisiblethings kernel: [    0.121812] pci 0000:00:1f.2: reg 0x24: [mem 0xf7d11000-0xf7d117ff]
Mar 13 02:14:35 invisiblethings kernel: [    0.121834] pci 0000:00:1f.2: PME# supported from D3hot
Mar 13 02:14:35 invisiblethings kernel: [    0.121884] pci 0000:00:1f.3: [8086:8c22] type 00 class 0x0c0500
Mar 13 02:14:35 invisiblethings kernel: [    0.121899] pci 0000:00:1f.3: reg 0x10: [mem 0xf7d10000-0xf7d100ff 64bit]
Mar 13 02:14:35 invisiblethings kernel: [    0.121917] pci 0000:00:1f.3: reg 0x20: [io  0xf040-0xf05f]
Mar 13 02:14:35 invisiblethings kernel: [    0.121999] pci 0000:00:01.0: PCI bridge to [bus 01]
Mar 13 02:14:35 invisiblethings kernel: [    0.122047] pci 0000:00:1c.0: PCI bridge to [bus 02]
Mar 13 02:14:35 invisiblethings kernel: [    0.122112] pci 0000:03:00.0: [10ec:8168] type 00 class 0x020000
Mar 13 02:14:35 invisiblethings kernel: [    0.122150] pci 0000:03:00.0: reg 0x10: [io  0xe000-0xe0ff]
Mar 13 02:14:35 invisiblethings kernel: [    0.122177] pci 0000:03:00.0: reg 0x18: [mem 0xf7c00000-0xf7c00fff 64bit]
Mar 13 02:14:35 invisiblethings kernel: [    0.122194] pci 0000:03:00.0: reg 0x20: [mem 0xf0000000-0xf0003fff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.122251] pci 0000:03:00.0: supports D1 D2
Mar 13 02:14:35 invisiblethings kernel: [    0.122252] pci 0000:03:00.0: PME# supported from D0 D1 D2 D3hot D3cold
Mar 13 02:14:35 invisiblethings kernel: [    0.122300] pci 0000:03:00.0: System wakeup disabled by ACPI
Mar 13 02:14:35 invisiblethings kernel: [    0.130349] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 02:14:35 invisiblethings kernel: [    0.130353] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
Mar 13 02:14:35 invisiblethings kernel: [    0.130356] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.130360] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.131010] ACPI: PCI Interrupt Link [LNKA] (IRQs 3 4 5 6 10 *11 12 14 15)
Mar 13 02:14:35 invisiblethings kernel: [    0.131045] ACPI: PCI Interrupt Link [LNKB] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 02:14:35 invisiblethings kernel: [    0.131079] ACPI: PCI Interrupt Link [LNKC] (IRQs *3 4 5 6 10 11 12 14 15)
Mar 13 02:14:35 invisiblethings kernel: [    0.131112] ACPI: PCI Interrupt Link [LNKD] (IRQs 3 4 5 6 *10 11 12 14 15)
Mar 13 02:14:35 invisiblethings kernel: [    0.131144] ACPI: PCI Interrupt Link [LNKE] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 02:14:35 invisiblethings kernel: [    0.131176] ACPI: PCI Interrupt Link [LNKF] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 02:14:35 invisiblethings kernel: [    0.131208] ACPI: PCI Interrupt Link [LNKG] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 02:14:35 invisiblethings kernel: [    0.131240] ACPI: PCI Interrupt Link [LNKH] (IRQs 3 4 *5 6 10 11 12 14 15)
Mar 13 02:14:35 invisiblethings kernel: [    0.131449] ACPI: Enabled 6 GPEs in block 00 to 3F
Mar 13 02:14:35 invisiblethings kernel: [    0.131530] vgaarb: setting as boot device: PCI:0000:00:02.0
Mar 13 02:14:35 invisiblethings kernel: [    0.131532] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
Mar 13 02:14:35 invisiblethings kernel: [    0.131533] vgaarb: loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.131534] vgaarb: bridge control possible 0000:00:02.0
Mar 13 02:14:35 invisiblethings kernel: [    0.131711] SCSI subsystem initialized
Mar 13 02:14:35 invisiblethings kernel: [    0.131742] libata version 3.00 loaded.
Mar 13 02:14:35 invisiblethings kernel: [    0.131757] ACPI: bus type USB registered
Mar 13 02:14:35 invisiblethings kernel: [    0.131770] usbcore: registered new interface driver usbfs
Mar 13 02:14:35 invisiblethings kernel: [    0.131776] usbcore: registered new interface driver hub
Mar 13 02:14:35 invisiblethings kernel: [    0.131782] usbcore: registered new device driver usb
Mar 13 02:14:35 invisiblethings kernel: [    0.131874] PCI: Using ACPI for IRQ routing
Mar 13 02:14:35 invisiblethings kernel: [    0.133113] PCI: pci_cache_line_size set to 64 bytes
Mar 13 02:14:35 invisiblethings kernel: [    0.133142] e820: reserve RAM buffer [mem 0x0009d800-0x0009ffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.133143] e820: reserve RAM buffer [mem 0xc8b3c000-0xcbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.133144] e820: reserve RAM buffer [mem 0xc9602000-0xcbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.133145] e820: reserve RAM buffer [mem 0xdbaf7000-0xdbffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.133146] e820: reserve RAM buffer [mem 0x11fe00000-0x11fffffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.133222] NetLabel: Initializing
Mar 13 02:14:35 invisiblethings kernel: [    0.133223] NetLabel:  domain hash size = 128
Mar 13 02:14:35 invisiblethings kernel: [    0.133224] NetLabel:  protocols = UNLABELED CIPSOv4
Mar 13 02:14:35 invisiblethings kernel: [    0.133233] NetLabel:  unlabeled traffic allowed by default
Mar 13 02:14:35 invisiblethings kernel: [    0.133283] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0, 0, 0, 0, 0, 0
Mar 13 02:14:35 invisiblethings kernel: [    0.133287] hpet0: 8 comparators, 64-bit 14.318180 MHz counter
Mar 13 02:14:35 invisiblethings kernel: [    0.135309] clocksource: Switched to clocksource hpet
Mar 13 02:14:35 invisiblethings kernel: [    0.140133] AppArmor: AppArmor Filesystem Enabled
Mar 13 02:14:35 invisiblethings kernel: [    0.140193] pnp: PnP ACPI init
Mar 13 02:14:35 invisiblethings kernel: [    0.140364] system 00:00: [io  0x0800-0x087f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140367] system 00:00: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140386] pnp 00:01: Plug and Play ACPI device, IDs PNP0b00 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140410] system 00:02: [io  0x1854-0x1857] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140412] system 00:02: Plug and Play ACPI device, IDs INT3f0d PNP0c02 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140549] system 00:03: [io  0x0a00-0x0a1f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140550] system 00:03: [io  0x0a20-0x0a2f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140551] system 00:03: [io  0x0a30-0x0a3f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140552] system 00:03: [io  0x0a40-0x0a7f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140553] system 00:03: [io  0x0a50-0x0a5f] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140555] system 00:03: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140602] system 00:04: [io  0x04d0-0x04d1] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140604] system 00:04: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140732] pnp 00:05: Plug and Play ACPI device, IDs PNP0c31 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.140932] system 00:06: [mem 0xfed1c000-0xfed1ffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140934] system 00:06: [mem 0xfed10000-0xfed17fff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140935] system 00:06: [mem 0xfed18000-0xfed18fff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140936] system 00:06: [mem 0xfed19000-0xfed19fff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140937] system 00:06: [mem 0xf8000000-0xfbffffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140938] system 00:06: [mem 0xfed20000-0xfed3ffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140939] system 00:06: [mem 0xfed90000-0xfed93fff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140940] system 00:06: [mem 0xfed45000-0xfed8ffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140941] system 00:06: [mem 0xff000000-0xffffffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140943] system 00:06: [mem 0xfee00000-0xfeefffff] could not be reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140944] system 00:06: [mem 0xf7fe0000-0xf7feffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140945] system 00:06: [mem 0xf7ff0000-0xf7ffffff] has been reserved
Mar 13 02:14:35 invisiblethings kernel: [    0.140947] system 00:06: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 02:14:35 invisiblethings kernel: [    0.141075] pnp: PnP ACPI: found 7 devices
Mar 13 02:14:35 invisiblethings kernel: [    0.146827] clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns
Mar 13 02:14:35 invisiblethings kernel: [    0.146843] pci 0000:00:1c.0: bridge window [io  0x1000-0x0fff] to [bus 02] add_size 1000
Mar 13 02:14:35 invisiblethings kernel: [    0.146845] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff 64bit pref] to [bus 02] add_size 200000 add_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146846] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff] to [bus 02] add_size 200000 add_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146854] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x000fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146855] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x002fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146857] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x000fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146858] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x002fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 02:14:35 invisiblethings kernel: [    0.146859] pci 0000:00:1c.0: res[13]=[io  0x1000-0x0fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 02:14:35 invisiblethings kernel: [    0.146860] pci 0000:00:1c.0: res[13]=[io  0x1000-0x1fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 02:14:35 invisiblethings kernel: [    0.146864] pci 0000:00:1c.0: BAR 14: assigned [mem 0xdf200000-0xdf3fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146869] pci 0000:00:1c.0: BAR 15: assigned [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.146871] pci 0000:00:1c.0: BAR 13: assigned [io  0x2000-0x2fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146872] pci 0000:00:01.0: PCI bridge to [bus 01]
Mar 13 02:14:35 invisiblethings kernel: [    0.146877] pci 0000:00:1c.0: PCI bridge to [bus 02]
Mar 13 02:14:35 invisiblethings kernel: [    0.146879] pci 0000:00:1c.0:  bridge window [io  0x2000-0x2fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146884] pci 0000:00:1c.0:  bridge window [mem 0xdf200000-0xdf3fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146887] pci 0000:00:1c.0:  bridge window [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.146892] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 02:14:35 invisiblethings kernel: [    0.146894] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146898] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146902] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.146907] pci_bus 0000:00: resource 4 [io  0x0000-0x0cf7 window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146908] pci_bus 0000:00: resource 5 [io  0x0d00-0xffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146909] pci_bus 0000:00: resource 6 [mem 0x000a0000-0x000bffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146910] pci_bus 0000:00: resource 7 [mem 0x000d0000-0x000d3fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146911] pci_bus 0000:00: resource 8 [mem 0x000d4000-0x000d7fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146912] pci_bus 0000:00: resource 9 [mem 0x000d8000-0x000dbfff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146913] pci_bus 0000:00: resource 10 [mem 0x000dc000-0x000dffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146914] pci_bus 0000:00: resource 11 [mem 0x000e0000-0x000e3fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146915] pci_bus 0000:00: resource 12 [mem 0x000e4000-0x000e7fff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146916] pci_bus 0000:00: resource 13 [mem 0xdf200000-0xfeafffff window]
Mar 13 02:14:35 invisiblethings kernel: [    0.146917] pci_bus 0000:02: resource 0 [io  0x2000-0x2fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146918] pci_bus 0000:02: resource 1 [mem 0xdf200000-0xdf3fffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146919] pci_bus 0000:02: resource 2 [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.146920] pci_bus 0000:03: resource 0 [io  0xe000-0xefff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146921] pci_bus 0000:03: resource 1 [mem 0xf7c00000-0xf7cfffff]
Mar 13 02:14:35 invisiblethings kernel: [    0.146922] pci_bus 0000:03: resource 2 [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 02:14:35 invisiblethings kernel: [    0.146944] NET: Registered protocol family 2
Mar 13 02:14:35 invisiblethings kernel: [    0.147057] TCP established hash table entries: 32768 (order: 6, 262144 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.147134] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.147251] TCP: Hash tables configured (established 32768 bind 32768)
Mar 13 02:14:35 invisiblethings kernel: [    0.147273] UDP hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.147289] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.147334] NET: Registered protocol family 1
Mar 13 02:14:35 invisiblethings kernel: [    0.147345] pci 0000:00:02.0: Video device with shadowed ROM
Mar 13 02:14:35 invisiblethings kernel: [    0.187427] PCI: CLS 64 bytes, default 64
Mar 13 02:14:35 invisiblethings kernel: [    0.187471] Trying to unpack rootfs image as initramfs...
Mar 13 02:14:35 invisiblethings kernel: [    0.572693] Freeing initrd memory: 34964K (ffff880033ba6000 - ffff880035dcb000)
Mar 13 02:14:35 invisiblethings kernel: [    0.572705] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
Mar 13 02:14:35 invisiblethings kernel: [    0.572706] software IO TLB [mem 0xd7af7000-0xdbaf7000] (64MB) mapped at [ffff8800d7af7000-ffff8800dbaf6fff]
Mar 13 02:14:35 invisiblethings kernel: [    0.572771] RAPL PMU detected, API unit is 2^-32 Joules, 4 fixed counters 655360 ms ovfl timer
Mar 13 02:14:35 invisiblethings kernel: [    0.572772] hw unit of domain pp0-core 2^-14 Joules
Mar 13 02:14:35 invisiblethings kernel: [    0.572772] hw unit of domain package 2^-14 Joules
Mar 13 02:14:35 invisiblethings kernel: [    0.572773] hw unit of domain dram 2^-14 Joules
Mar 13 02:14:35 invisiblethings kernel: [    0.572773] hw unit of domain pp1-gpu 2^-14 Joules
Mar 13 02:14:35 invisiblethings kernel: [    0.572870] microcode: CPU0 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 02:14:35 invisiblethings kernel: [    0.572873] microcode: CPU1 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 02:14:35 invisiblethings kernel: [    0.572920] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
Mar 13 02:14:35 invisiblethings kernel: [    0.572974] Scanning for low memory corruption every 60 seconds
Mar 13 02:14:35 invisiblethings kernel: [    0.573199] futex hash table entries: 512 (order: 3, 32768 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.573214] Initialise system trusted keyring
Mar 13 02:14:35 invisiblethings kernel: [    0.573231] audit: initializing netlink subsys (disabled)
Mar 13 02:14:35 invisiblethings kernel: [    0.573244] audit: type=2000 audit(1457831637.572:1): initialized
Mar 13 02:14:35 invisiblethings kernel: [    0.573485] HugeTLB registered 1 GB page size, pre-allocated 0 pages
Mar 13 02:14:35 invisiblethings kernel: [    0.573486] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mar 13 02:14:35 invisiblethings kernel: [    0.574476] zpool: loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.574479] zbud: loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.574607] VFS: Disk quotas dquot_6.6.0
Mar 13 02:14:35 invisiblethings kernel: [    0.574630] VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mar 13 02:14:35 invisiblethings kernel: [    0.574942] fuse init (API version 7.23)
Mar 13 02:14:35 invisiblethings kernel: [    0.575036] Key type big_key registered
Mar 13 02:14:35 invisiblethings kernel: [    0.575291] Key type asymmetric registered
Mar 13 02:14:35 invisiblethings kernel: [    0.575294] Asymmetric key parser 'x509' registered
Mar 13 02:14:35 invisiblethings kernel: [    0.575304] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 249)
Mar 13 02:14:35 invisiblethings kernel: [    0.575323] io scheduler noop registered
Mar 13 02:14:35 invisiblethings kernel: [    0.575325] io scheduler deadline registered (default)
Mar 13 02:14:35 invisiblethings kernel: [    0.575345] io scheduler cfq registered
Mar 13 02:14:35 invisiblethings kernel: [    0.575750] pcieport 0000:00:01.0: Signaling PME through PCIe PME interrupt
Mar 13 02:14:35 invisiblethings kernel: [    0.575752] pcie_pme 0000:00:01.0:pcie01: service driver pcie_pme loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.575767] pcieport 0000:00:1c.0: Signaling PME through PCIe PME interrupt
Mar 13 02:14:35 invisiblethings kernel: [    0.575770] pcie_pme 0000:00:1c.0:pcie01: service driver pcie_pme loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.575784] pcieport 0000:00:1c.3: Signaling PME through PCIe PME interrupt
Mar 13 02:14:35 invisiblethings kernel: [    0.575785] pci 0000:03:00.0: Signaling PME through PCIe PME interrupt
Mar 13 02:14:35 invisiblethings kernel: [    0.575789] pcie_pme 0000:00:1c.3:pcie01: service driver pcie_pme loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.575793] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
Mar 13 02:14:35 invisiblethings kernel: [    0.575801] pciehp 0000:00:1c.0:pcie04: Slot #0 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ LLActRep+
Mar 13 02:14:35 invisiblethings kernel: [    0.575817] pciehp 0000:00:1c.0:pcie04: service driver pciehp loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.575820] pciehp: PCI Express Hot Plug Controller Driver version: 0.4
Mar 13 02:14:35 invisiblethings kernel: [    0.575841] vesafb: mode is 1920x1080x32, linelength=7680, pages=0
Mar 13 02:14:35 invisiblethings kernel: [    0.575842] vesafb: scrolling: redraw
Mar 13 02:14:35 invisiblethings kernel: [    0.575843] vesafb: Truecolor: size=8:8:8:8, shift=24:16:8:0
Mar 13 02:14:35 invisiblethings kernel: [    0.575851] vesafb: framebuffer at 0xe0000000, mapped to 0xffffc90000800000, using 8128k, total 8128k
Mar 13 02:14:35 invisiblethings kernel: [    0.575922] Console: switching to colour frame buffer device 240x67
Mar 13 02:14:35 invisiblethings kernel: [    0.575938] fb0: VESA VGA frame buffer device
Mar 13 02:14:35 invisiblethings kernel: [    0.575949] intel_idle: MWAIT substates: 0x2120
Mar 13 02:14:35 invisiblethings kernel: [    0.575950] intel_idle: v0.4 model 0x3C
Mar 13 02:14:35 invisiblethings kernel: [    0.575951] intel_idle: lapic_timer_reliable_states 0xffffffff
Mar 13 02:14:35 invisiblethings kernel: [    0.576062] input: Power Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input0
Mar 13 02:14:35 invisiblethings kernel: [    0.576065] ACPI: Power Button [PWRB]
Mar 13 02:14:35 invisiblethings kernel: [    0.576088] input: Sleep Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1
Mar 13 02:14:35 invisiblethings kernel: [    0.576089] ACPI: Sleep Button [SLPB]
Mar 13 02:14:35 invisiblethings kernel: [    0.576111] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input2
Mar 13 02:14:35 invisiblethings kernel: [    0.576113] ACPI: Power Button [PWRF]
Mar 13 02:14:35 invisiblethings kernel: [    0.576592] thermal LNXTHERM:00: registered as thermal_zone0
Mar 13 02:14:35 invisiblethings kernel: [    0.576593] ACPI: Thermal Zone [TZ00] (28 C)
Mar 13 02:14:35 invisiblethings kernel: [    0.576717] thermal LNXTHERM:01: registered as thermal_zone1
Mar 13 02:14:35 invisiblethings kernel: [    0.576718] ACPI: Thermal Zone [TZ01] (30 C)
Mar 13 02:14:35 invisiblethings kernel: [    0.576768] GHES: HEST is not enabled!
Mar 13 02:14:35 invisiblethings kernel: [    0.576825] Serial: 8250/16550 driver, 32 ports, IRQ sharing enabled
Mar 13 02:14:35 invisiblethings kernel: [    0.577912] Linux agpgart interface v0.103
Mar 13 02:14:35 invisiblethings kernel: [    0.651782] tpm_tis 00:05: 1.2 TPM (device-id 0xB, rev-id 16)
Mar 13 02:14:35 invisiblethings kernel: [    0.953868] brd: module loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.954399] loop: module loaded
Mar 13 02:14:35 invisiblethings kernel: [    0.954543] libphy: Fixed MDIO Bus: probed
Mar 13 02:14:35 invisiblethings kernel: [    0.954545] tun: Universal TUN/TAP device driver, 1.6
Mar 13 02:14:35 invisiblethings kernel: [    0.954545] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Mar 13 02:14:35 invisiblethings kernel: [    0.954572] PPP generic driver version 2.4.2
Mar 13 02:14:35 invisiblethings kernel: [    0.954688] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.954692] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 1
Mar 13 02:14:35 invisiblethings kernel: [    0.954770] xhci_hcd 0000:00:14.0: hcc params 0x200077c1 hci version 0x100 quirks 0x00009810
Mar 13 02:14:35 invisiblethings kernel: [    0.954775] xhci_hcd 0000:00:14.0: cache line size of 64 is not supported
Mar 13 02:14:35 invisiblethings kernel: [    0.954840] usb usb1: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 02:14:35 invisiblethings kernel: [    0.954841] usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 02:14:35 invisiblethings kernel: [    0.954842] usb usb1: Product: xHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.954843] usb usb1: Manufacturer: Linux 4.2.0-16-generic xhci-hcd
Mar 13 02:14:35 invisiblethings kernel: [    0.954844] usb usb1: SerialNumber: 0000:00:14.0
Mar 13 02:14:35 invisiblethings kernel: [    0.954919] hub 1-0:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    0.954929] hub 1-0:1.0: 10 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    0.956583] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.956585] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 2
Mar 13 02:14:35 invisiblethings kernel: [    0.956607] usb usb2: New USB device found, idVendor=1d6b, idProduct=0003
Mar 13 02:14:35 invisiblethings kernel: [    0.956608] usb usb2: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 02:14:35 invisiblethings kernel: [    0.956609] usb usb2: Product: xHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.956610] usb usb2: Manufacturer: Linux 4.2.0-16-generic xhci-hcd
Mar 13 02:14:35 invisiblethings kernel: [    0.956611] usb usb2: SerialNumber: 0000:00:14.0
Mar 13 02:14:35 invisiblethings kernel: [    0.956692] hub 2-0:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    0.956697] hub 2-0:1.0: 2 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    0.957100] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mar 13 02:14:35 invisiblethings kernel: [    0.957104] ehci-pci: EHCI PCI platform driver
Mar 13 02:14:35 invisiblethings kernel: [    0.957164] ehci-pci 0000:00:1a.0: EHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.957167] ehci-pci 0000:00:1a.0: new USB bus registered, assigned bus number 3
Mar 13 02:14:35 invisiblethings kernel: [    0.957176] ehci-pci 0000:00:1a.0: debug port 2
Mar 13 02:14:35 invisiblethings kernel: [    0.961074] ehci-pci 0000:00:1a.0: cache line size of 64 is not supported
Mar 13 02:14:35 invisiblethings kernel: [    0.961081] ehci-pci 0000:00:1a.0: irq 16, io mem 0xf7d13000
Mar 13 02:14:35 invisiblethings kernel: [    0.976028] ehci-pci 0000:00:1a.0: USB 2.0 started, EHCI 1.00
Mar 13 02:14:35 invisiblethings kernel: [    0.976059] usb usb3: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 02:14:35 invisiblethings kernel: [    0.976061] usb usb3: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 02:14:35 invisiblethings kernel: [    0.976062] usb usb3: Product: EHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.976063] usb usb3: Manufacturer: Linux 4.2.0-16-generic ehci_hcd
Mar 13 02:14:35 invisiblethings kernel: [    0.976064] usb usb3: SerialNumber: 0000:00:1a.0
Mar 13 02:14:35 invisiblethings kernel: [    0.976186] hub 3-0:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    0.976191] hub 3-0:1.0: 2 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    0.976327] ehci-pci 0000:00:1d.0: EHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.976331] ehci-pci 0000:00:1d.0: new USB bus registered, assigned bus number 4
Mar 13 02:14:35 invisiblethings kernel: [    0.976340] ehci-pci 0000:00:1d.0: debug port 2
Mar 13 02:14:35 invisiblethings kernel: [    0.980224] ehci-pci 0000:00:1d.0: cache line size of 64 is not supported
Mar 13 02:14:35 invisiblethings kernel: [    0.980229] ehci-pci 0000:00:1d.0: irq 23, io mem 0xf7d12000
Mar 13 02:14:35 invisiblethings kernel: [    0.992044] ehci-pci 0000:00:1d.0: USB 2.0 started, EHCI 1.00
Mar 13 02:14:35 invisiblethings kernel: [    0.992072] usb usb4: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 02:14:35 invisiblethings kernel: [    0.992073] usb usb4: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 02:14:35 invisiblethings kernel: [    0.992074] usb usb4: Product: EHCI Host Controller
Mar 13 02:14:35 invisiblethings kernel: [    0.992075] usb usb4: Manufacturer: Linux 4.2.0-16-generic ehci_hcd
Mar 13 02:14:35 invisiblethings kernel: [    0.992076] usb usb4: SerialNumber: 0000:00:1d.0
Mar 13 02:14:35 invisiblethings kernel: [    0.992200] hub 4-0:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    0.992204] hub 4-0:1.0: 2 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    0.992283] ehci-platform: EHCI generic platform driver
Mar 13 02:14:35 invisiblethings kernel: [    0.992291] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mar 13 02:14:35 invisiblethings kernel: [    0.992294] ohci-pci: OHCI PCI platform driver
Mar 13 02:14:35 invisiblethings kernel: [    0.992300] ohci-platform: OHCI generic platform driver
Mar 13 02:14:35 invisiblethings kernel: [    0.992306] uhci_hcd: USB Universal Host Controller Interface driver
Mar 13 02:14:35 invisiblethings kernel: [    0.992336] i8042: PNP: No PS/2 controller found. Probing ports directly.
Mar 13 02:14:35 invisiblethings kernel: [    0.992753] serio: i8042 KBD port at 0x60,0x64 irq 1
Mar 13 02:14:35 invisiblethings kernel: [    0.992758] serio: i8042 AUX port at 0x60,0x64 irq 12
Mar 13 02:14:35 invisiblethings kernel: [    0.992956] mousedev: PS/2 mouse device common for all mice
Mar 13 02:14:35 invisiblethings kernel: [    0.993236] rtc_cmos 00:01: RTC can wake from S4
Mar 13 02:14:35 invisiblethings kernel: [    0.993343] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0
Mar 13 02:14:35 invisiblethings kernel: [    0.993367] rtc_cmos 00:01: alarms up to one month, y3k, 242 bytes nvram, hpet irqs
Mar 13 02:14:35 invisiblethings kernel: [    0.993372] i2c /dev entries driver
Mar 13 02:14:35 invisiblethings kernel: [    0.993425] device-mapper: uevent: version 1.0.3
Mar 13 02:14:35 invisiblethings kernel: [    0.993472] device-mapper: ioctl: 4.33.0-ioctl (2015-8-18) initialised: dm-devel@redhat.com
Mar 13 02:14:35 invisiblethings kernel: [    0.993484] Intel P-state driver initializing.
Mar 13 02:14:35 invisiblethings kernel: [    0.993573] ledtrig-cpu: registered to indicate activity on CPUs
Mar 13 02:14:35 invisiblethings kernel: [    0.993842] PCCT header not found.
Mar 13 02:14:35 invisiblethings kernel: [    0.994350] NET: Registered protocol family 10
Mar 13 02:14:35 invisiblethings kernel: [    0.994745] NET: Registered protocol family 17
Mar 13 02:14:35 invisiblethings kernel: [    0.994773] Key type dns_resolver registered
Mar 13 02:14:35 invisiblethings kernel: [    0.995494] Loading compiled-in X.509 certificates
Mar 13 02:14:35 invisiblethings kernel: [    0.997758] Loaded X.509 cert 'Build time autogenerated kernel key: 6a1c9c21f04ab86fd1d7ced6ca113540fc8e35b6'
Mar 13 02:14:35 invisiblethings kernel: [    0.997793] registered taskstats version 1
Mar 13 02:14:35 invisiblethings kernel: [    0.997843] zswap: loading zswap
Mar 13 02:14:35 invisiblethings kernel: [    0.997848] zswap: using zbud pool
Mar 13 02:14:35 invisiblethings kernel: [    0.997858] zswap: using lzo compressor
Mar 13 02:14:35 invisiblethings kernel: [    1.000647] Key type trusted registered
Mar 13 02:14:35 invisiblethings kernel: [    1.002628] Key type encrypted registered
Mar 13 02:14:35 invisiblethings kernel: [    1.002634] AppArmor: AppArmor sha1 policy hashing enabled
Mar 13 02:14:35 invisiblethings kernel: [    1.268267] usb 1-1: new low-speed USB device number 2 using xhci_hcd
Mar 13 02:14:35 invisiblethings kernel: [    1.288283] usb 3-1: new high-speed USB device number 2 using ehci-pci
Mar 13 02:14:35 invisiblethings kernel: [    1.304296] usb 4-1: new high-speed USB device number 2 using ehci-pci
Mar 13 02:14:35 invisiblethings kernel: [    1.401699] usb 1-1: New USB device found, idVendor=0461, idProduct=0010
Mar 13 02:14:35 invisiblethings kernel: [    1.401701] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 02:14:35 invisiblethings kernel: [    1.401703] usb 1-1: Product: USB Keyboard
Mar 13 02:14:35 invisiblethings kernel: [    1.401704] usb 1-1: Manufacturer: NOVATEK
Mar 13 02:14:35 invisiblethings kernel: [    1.401821] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 02:14:35 invisiblethings kernel: [    1.401824] usb 1-1: ep 0x82 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 02:14:35 invisiblethings kernel: [    1.420772] usb 3-1: New USB device found, idVendor=8087, idProduct=8008
Mar 13 02:14:35 invisiblethings kernel: [    1.420774] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 02:14:35 invisiblethings kernel: [    1.421044] hub 3-1:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    1.421147] hub 3-1:1.0: 4 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    1.436808] usb 4-1: New USB device found, idVendor=8087, idProduct=8000
Mar 13 02:14:35 invisiblethings kernel: [    1.436810] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 02:14:35 invisiblethings kernel: [    1.437088] hub 4-1:1.0: USB hub found
Mar 13 02:14:35 invisiblethings kernel: [    1.437177] hub 4-1:1.0: 6 ports detected
Mar 13 02:14:35 invisiblethings kernel: [    1.568504] usb 1-2: new low-speed USB device number 3 using xhci_hcd
Mar 13 02:14:35 invisiblethings kernel: [    1.572510] tsc: Refined TSC clocksource calibration: 3192.606 MHz
Mar 13 02:14:35 invisiblethings kernel: [    1.572512] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x2e050166e04, max_idle_ns: 440795273449 ns
Mar 13 02:14:35 invisiblethings kernel: [    1.696703] evm: HMAC attrs: 0x1
Mar 13 02:14:35 invisiblethings kernel: [    1.697121]  Magic number: 8:228:205
Mar 13 02:14:35 invisiblethings kernel: [    1.697169] acpi device:2d: hash matches
Mar 13 02:14:35 invisiblethings kernel: [    1.697231] rtc_cmos 00:01: setting system clock to 2016-03-13 01:13:58 UTC (1457831638)
Mar 13 02:14:35 invisiblethings kernel: [    1.697272] BIOS EDD facility v0.16 2004-Jun-25, 0 devices found
Mar 13 02:14:35 invisiblethings kernel: [    1.697273] EDD information not available.
Mar 13 02:14:35 invisiblethings kernel: [    1.697330] PM: Hibernation image not present or could not be loaded.
Mar 13 02:14:35 invisiblethings kernel: [    1.697544] Freeing unused kernel memory: 1460K (ffffffff81d37000 - ffffffff81ea4000)
Mar 13 02:14:35 invisiblethings kernel: [    1.697545] Write protecting the kernel read-only data: 12288k
Mar 13 02:14:35 invisiblethings kernel: [    1.697643] Freeing unused kernel memory: 36K (ffff8800017f7000 - ffff880001800000)
Mar 13 02:14:35 invisiblethings kernel: [    1.697696] Freeing unused kernel memory: 296K (ffff880001bb6000 - ffff880001c00000)
Mar 13 02:14:35 invisiblethings kernel: [    1.700036] usb 1-2: New USB device found, idVendor=03f0, idProduct=094a
Mar 13 02:14:35 invisiblethings kernel: [    1.700039] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 02:14:35 invisiblethings kernel: [    1.700040] usb 1-2: Product: HP USB Optical Mouse
Mar 13 02:14:35 invisiblethings kernel: [    1.700041] usb 1-2: Manufacturer: PixArt
Mar 13 02:14:35 invisiblethings kernel: [    1.700107] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 02:14:35 invisiblethings kernel: [    1.705336] random: systemd-udevd urandom read with 4 bits of entropy available
Mar 13 02:14:35 invisiblethings kernel: [    1.738352] [drm] Initialized drm 1.1.0 20060810
Mar 13 02:14:35 invisiblethings kernel: [    1.738726] ahci 0000:00:1f.2: version 3.0
Mar 13 02:14:35 invisiblethings kernel: [    1.738874] ahci 0000:00:1f.2: AHCI 0001.0300 32 slots 4 ports 6 Gbps 0x11 impl SATA mode
Mar 13 02:14:35 invisiblethings kernel: [    1.738876] ahci 0000:00:1f.2: flags: 64bit ncq pm led clo pio slum part ems
Mar 13 02:14:35 invisiblethings kernel: [    1.753955] wmi: Mapper loaded
Mar 13 02:14:35 invisiblethings kernel: [    1.754744] scsi host0: ahci
Mar 13 02:14:35 invisiblethings kernel: [    1.757635] hidraw: raw HID events driver (C) Jiri Kosina
Mar 13 02:14:35 invisiblethings kernel: [    1.758610] scsi host1: ahci
Mar 13 02:14:35 invisiblethings kernel: [    1.759896] scsi host2: ahci
Mar 13 02:14:35 invisiblethings kernel: [    1.759953] scsi host3: ahci
Mar 13 02:14:35 invisiblethings kernel: [    1.759998] scsi host4: ahci
Mar 13 02:14:35 invisiblethings kernel: [    1.760028] ata1: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11100 irq 28
Mar 13 02:14:35 invisiblethings kernel: [    1.760029] ata2: DUMMY
Mar 13 02:14:35 invisiblethings kernel: [    1.760030] ata3: DUMMY
Mar 13 02:14:35 invisiblethings kernel: [    1.760030] ata4: DUMMY
Mar 13 02:14:35 invisiblethings kernel: [    1.760033] ata5: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11300 irq 28
Mar 13 02:14:35 invisiblethings kernel: [    1.760472] [drm] Memory usable by graphics device = 2048M
Mar 13 02:14:35 invisiblethings kernel: [    1.760474] checking generic (e0000000 7f0000) vs hw (e0000000 10000000)
Mar 13 02:14:35 invisiblethings kernel: [    1.760475] fb: switching to inteldrmfb from VESA VGA
Mar 13 02:14:35 invisiblethings kernel: [    1.760496] Console: switching to colour dummy device 80x25
Mar 13 02:14:35 invisiblethings kernel: [    1.760534] [drm] Replacing VGA console driver
Mar 13 02:14:35 invisiblethings kernel: [    1.760970] r8169 Gigabit Ethernet driver 2.3LK-NAPI loaded
Mar 13 02:14:35 invisiblethings kernel: [    1.760976] r8169 0000:03:00.0: can't disable ASPM; OS doesn't have ASPM control
Mar 13 02:14:35 invisiblethings kernel: [    1.771534] r8169 0000:03:00.0 eth0: RTL8168g/8111g at 0xffffc9000078e000, 48:0f:cf:36:52:2a, XID 0c000800 IRQ 29
Mar 13 02:14:35 invisiblethings kernel: [    1.771537] r8169 0000:03:00.0 eth0: jumbo features [frames: 9200 bytes, tx checksumming: ko]
Mar 13 02:14:35 invisiblethings kernel: [    1.771660] usbcore: registered new interface driver usbhid
Mar 13 02:14:35 invisiblethings kernel: [    1.771661] usbhid: USB HID core driver
Mar 13 02:14:35 invisiblethings kernel: [    1.777210] [drm] Supports vblank timestamp caching Rev 2 (21.10.2013).
Mar 13 02:14:35 invisiblethings kernel: [    1.777213] [drm] Driver supports precise vblank timestamp query.
Mar 13 02:14:35 invisiblethings kernel: [    1.777324] vgaarb: device changed decodes: PCI:0000:00:02.0,olddecodes=io+mem,decodes=io+mem:owns=io+mem
Mar 13 02:14:35 invisiblethings kernel: [    1.784987] ACPI: Video Device [GFX0] (multi-head: yes  rom: no  post: no)
Mar 13 02:14:35 invisiblethings kernel: [    1.785179] input: Video Bus as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A08:00/LNXVIDEO:00/input/input6
Mar 13 02:14:35 invisiblethings kernel: [    1.785250] [drm] Initialized i915 1.6.0 20150522 for 0000:00:02.0 on minor 0
Mar 13 02:14:35 invisiblethings kernel: [    1.806831] fbcon: inteldrmfb (fb0) is primary device
Mar 13 02:14:35 invisiblethings kernel: [    1.806881] Console: switching to colour frame buffer device 240x67
Mar 13 02:14:35 invisiblethings kernel: [    1.806900] i915 0000:00:02.0: fb0: inteldrmfb frame buffer device
Mar 13 02:14:35 invisiblethings kernel: [    1.806901] i915 0000:00:02.0: registered panic notifier
Mar 13 02:14:35 invisiblethings kernel: [    1.807379] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:0461:0010.0001/input/input7
Mar 13 02:14:35 invisiblethings kernel: [    1.809327] r8169 0000:03:00.0 enp3s0: renamed from eth0
Mar 13 02:14:35 invisiblethings kernel: [    1.860893] hid-generic 0003:0461:0010.0001: input,hidraw0: USB HID v1.10 Keyboard [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input0
Mar 13 02:14:35 invisiblethings kernel: [    1.861833] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.1/0003:0461:0010.0002/input/input8
Mar 13 02:14:35 invisiblethings kernel: [    1.916931] hid-generic 0003:0461:0010.0002: input,hidraw1: USB HID v1.10 Device [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input1
Mar 13 02:14:35 invisiblethings kernel: [    1.917004] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:03F0:094A.0003/input/input9
Mar 13 02:14:35 invisiblethings kernel: [    1.917053] hid-generic 0003:03F0:094A.0003: input,hidraw2: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-2/input0
Mar 13 02:14:35 invisiblethings kernel: [    2.076926] ata1: SATA link up 6.0 Gbps (SStatus 133 SControl 300)
Mar 13 02:14:35 invisiblethings kernel: [    2.078022] ata1.00: ATA-8: WDC WD5000AAKX-60U6AA0, 18.01H18, max UDMA/100
Mar 13 02:14:35 invisiblethings kernel: [    2.078024] ata1.00: 976773168 sectors, multi 16: LBA48 NCQ (depth 31/32), AA
Mar 13 02:14:35 invisiblethings kernel: [    2.079186] ata1.00: configured for UDMA/100
Mar 13 02:14:35 invisiblethings kernel: [    2.079355] scsi 0:0:0:0: Direct-Access    ATA      WDC WD5000AAKX-6 1H18 PQ: 0 ANSI: 5
Mar 13 02:14:35 invisiblethings kernel: [    2.079606] sd 0:0:0:0: [sda] 976773168 512-byte logical blocks: (500 GB/465 GiB)
Mar 13 02:14:35 invisiblethings kernel: [    2.079633] sd 0:0:0:0: [sda] Write Protect is off
Mar 13 02:14:35 invisiblethings kernel: [    2.079634] sd 0:0:0:0: [sda] Mode Sense: 00 3a 00 00
Mar 13 02:14:35 invisiblethings kernel: [    2.079647] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
Mar 13 02:14:35 invisiblethings kernel: [    2.079741] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mar 13 02:14:35 invisiblethings kernel: [    2.080925] ata5: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
Mar 13 02:14:35 invisiblethings kernel: [    2.082091] ata5.00: ATAPI: hp      DVD A  DH16AFSH, DHH6, max UDMA/133
Mar 13 02:14:35 invisiblethings kernel: [    2.083161] ata5.00: configured for UDMA/133
Mar 13 02:14:35 invisiblethings kernel: [    2.095811]  sda: sda1 sda2 < sda5 >
Mar 13 02:14:35 invisiblethings kernel: [    2.096166] sd 0:0:0:0: [sda] Attached SCSI disk
Mar 13 02:14:35 invisiblethings kernel: [    2.099539] scsi 4:0:0:0: CD-ROM            hp      DVD A  DH16AFSH  DHH6 PQ: 0 ANSI: 5
Mar 13 02:14:35 invisiblethings kernel: [    2.132852] sr 4:0:0:0: [sr0] scsi3-mmc drive: 40x/314x writer dvd-ram cd/rw xa/form2 cdda tray
Mar 13 02:14:35 invisiblethings kernel: [    2.132855] cdrom: Uniform CD-ROM driver Revision: 3.20
Mar 13 02:14:35 invisiblethings kernel: [    2.132943] sr 4:0:0:0: Attached scsi CD-ROM sr0
Mar 13 02:14:35 invisiblethings kernel: [    2.132975] sr 4:0:0:0: Attached scsi generic sg1 type 5
Mar 13 02:14:35 invisiblethings kernel: [    2.573452] clocksource: Switched to clocksource tsc
Mar 13 02:14:35 invisiblethings kernel: [  13.998544] random: nonblocking pool is initialized
Mar 13 02:14:35 invisiblethings kernel: [  17.501800] NET: Registered protocol family 38
Mar 13 02:14:35 invisiblethings kernel: [  30.011762] EXT4-fs (dm-1): mounted filesystem with ordered data mode. Opts: (null)
Mar 13 02:14:35 invisiblethings kernel: [  31.659965] lp: driver loaded but no devices found
Mar 13 02:14:35 invisiblethings kernel: [  31.676597] ppdev: user-space parallel port driver
Mar 13 02:14:35 invisiblethings kernel: [  32.660202] EXT4-fs (dm-1): re-mounted. Opts: errors=remount-ro
Mar 13 02:14:35 invisiblethings kernel: [  32.980531] shpchp: Standard Hot Plug PCI Controller Driver version: 0.4
Mar 13 02:14:35 invisiblethings kernel: [  33.246845] kvm: disabled by bios
Mar 13 02:14:35 invisiblethings kernel: [  33.266532] kvm: disabled by bios
Mar 13 02:14:35 invisiblethings kernel: [  33.352914] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 02:14:35 invisiblethings kernel: [  33.352918] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.352924] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.352947] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 02:14:35 invisiblethings kernel: [  33.352949] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.352952] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.352973] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 02:14:35 invisiblethings kernel: [  33.352974] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.352977] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.353017] input: HP WMI hotkeys as /devices/virtual/input/input10
Mar 13 02:14:35 invisiblethings kernel: [  33.353103] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 02:14:35 invisiblethings kernel: [  33.353105] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.353109] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.353129] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 02:14:35 invisiblethings kernel: [  33.353130] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.353133] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 02:14:35 invisiblethings kernel: [  33.629102] intel_rapl: Found RAPL domain package
Mar 13 02:14:35 invisiblethings kernel: [  33.629105] intel_rapl: Found RAPL domain core
Mar 13 02:14:35 invisiblethings kernel: [  33.629107] intel_rapl: Found RAPL domain uncore
Mar 13 02:14:35 invisiblethings kernel: [  33.629108] intel_rapl: Found RAPL domain dram
Mar 13 02:14:35 invisiblethings kernel: [  35.964131] Adding 4115964k swap on /dev/mapper/cryptswap1.  Priority:-1 extents:1 across:4115964k FS
Mar 13 02:14:35 invisiblethings kernel: [  36.107867] EXT4-fs (sda1): mounting ext2 file system using the ext4 subsystem
Mar 13 02:14:35 invisiblethings kernel: [  36.112307] EXT4-fs (sda1): mounted filesystem without journal. Opts: (null)
Mar 13 02:14:35 invisiblethings kernel: [  37.417109] audit: type=1400 audit(1457831674.183:2): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/lightdm/lightdm-guest-session" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.417115] audit: type=1400 audit(1457831674.183:3): apparmor="STATUS" operation="profile_load" profile="unconfined" name="chromium" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.427011] audit: type=1400 audit(1457831674.195:4): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/sbin/dhclient" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.427016] audit: type=1400 audit(1457831674.195:5): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.427019] audit: type=1400 audit(1457831674.195:6): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-helper" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.427022] audit: type=1400 audit(1457831674.195:7): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.446690] audit: type=1400 audit(1457831674.215:8): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.446697] audit: type=1400 audit(1457831674.215:9): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.446700] audit: type=1400 audit(1457831674.215:10): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince-previewer" pid=585 comm="apparmor_parser"
Mar 13 02:14:35 invisiblethings kernel: [  37.446703] audit: type=1400 audit(1457831674.215:11): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=585 comm="apparmor_parser"
Mar 13 02:14:36 invisiblethings kernel: [  39.300108] cgroup: new mount options do not match the existing superblock, will be ignored
Mar 13 02:14:37 invisiblethings kernel: [  41.185392] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 02:14:38 invisiblethings kernel: [  41.295061] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:14:38 invisiblethings kernel: [  41.295090] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 02:14:53 invisiblethings kernel: [  56.582332] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:14:53 invisiblethings kernel: [  56.582340] IPv6: ADDRCONF(NETDEV_CHANGE): enp3s0: link becomes ready
Mar 13 02:15:20 invisiblethings gnome-session[1542]: Entering running state
Mar 13 02:45:24 invisiblethings kernel: [ 1888.995074] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:45:27 invisiblethings kernel: [ 1891.888281] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:45:44 invisiblethings kernel: [ 1909.291247] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:46:21 invisiblethings kernel: [ 1946.234287] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:46:31 invisiblethings kernel: [ 1956.582402] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:47:06 invisiblethings kernel: [ 1991.443967] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:52:56 invisiblethings kernel: [ 2341.832704] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:53:29 invisiblethings kernel: [ 2375.027805] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:53:40 invisiblethings kernel: [ 2385.162880] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:54:14 invisiblethings kernel: [ 2420.021322] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:18:33 invisiblethings kernel: [ 3876.146960] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:18:36 invisiblethings kernel: [ 3878.934205] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:18:46 invisiblethings kernel: [ 3889.226711] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:19:21 invisiblethings kernel: [ 3924.262483] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:22:48 invisiblethings kernel: [ 4131.391265] r8169 0000:03:00.0 enp3s0: link down
Mar 13 02:22:51 invisiblethings kernel: [ 4134.079839] r8169 0000:03:00.0 enp3s0: link up
Mar 13 02:52:45 invisiblethings kernel: [ 5928.968591] ip_tables: (C) 2000-2006 Netfilter Core Team
Mar 13 03:27:18 invisiblethings kernel: [ 8003.678880] perf interrupt took too long (2531 > 2500), lowering kernel.perf_event_max_sample_rate to 50000
Mar 13 03:27:35 invisiblethings kernel: [ 8021.355456] audit_printk_skb: 39 callbacks suppressed
Mar 13 03:27:35 invisiblethings kernel: [ 8021.355459] audit: type=1400 audit(1457836055.718:25): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/sbin/ntpd" pid=9774 comm="apparmor_parser"
Mar 13 03:52:51 invisiblethings kernel: [ 9538.641447] SGI XFS with ACLs, security attributes, realtime, no debug enabled
Mar 13 03:52:51 invisiblethings kernel: [ 9538.691702] JFS: nTxBlock = 8192, nTxLock = 65536
Mar 13 03:52:51 invisiblethings kernel: [ 9538.731354] ntfs: driver 2.1.32 [Flags: R/O MODULE].
Mar 13 03:52:51 invisiblethings kernel: [ 9538.756883] QNX4 filesystem 0.2.3 registered.
Mar 13 03:52:51 invisiblethings kernel: [ 9538.848568] raid6: sse2x1  gen() 10173 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9538.916618] raid6: sse2x1  xor()  7975 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9538.984671] raid6: sse2x2  gen() 12929 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9539.052729] raid6: sse2x2  xor()  8705 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9539.120782] raid6: sse2x4  gen() 14934 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9539.188861] raid6: sse2x4  xor()  9403 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9539.188868] raid6: using algorithm sse2x4 gen() 14934 MB/s
Mar 13 03:52:52 invisiblethings kernel: [ 9539.188868] raid6: .... xor() 9403 MB/s, rmw enabled
Mar 13 03:52:52 invisiblethings kernel: [ 9539.188870] raid6: using ssse3x2 recovery algorithm
Mar 13 03:52:52 invisiblethings kernel: [ 9539.199299] xor: measuring software checksum speed
Mar 13 03:52:52 invisiblethings kernel: [ 9539.236875]    prefetch64-sse: 21308.000 MB/sec
Mar 13 03:52:52 invisiblethings kernel: [ 9539.276916]    generic_sse: 19267.000 MB/sec
Mar 13 03:52:52 invisiblethings kernel: [ 9539.276922] xor: using function: prefetch64-sse (21308.000 MB/sec)
Mar 13 03:52:52 invisiblethings kernel: [ 9539.323843] Btrfs loaded
Mar 13 03:52:52 invisiblethings kernel: [ 9539.728117] EXT4-fs (sda2): unable to read superblock
Mar 13 03:52:52 invisiblethings kernel: [ 9539.729088] EXT4-fs (sda2): unable to read superblock
Mar 13 03:52:52 invisiblethings kernel: [ 9539.730038] EXT4-fs (sda2): unable to read superblock
Mar 13 03:52:52 invisiblethings kernel: [ 9539.730990] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:52:52 invisiblethings kernel: [ 9539.730993] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:52:52 invisiblethings kernel: [ 9539.755011] XFS (sda2): Invalid superblock magic number
Mar 13 03:52:52 invisiblethings kernel: [ 9539.772730] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:52:52 invisiblethings kernel: [ 9539.772734] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:52:52 invisiblethings kernel: [ 9539.775381] MINIX-fs: unable to read superblock
Mar 13 03:52:52 invisiblethings kernel: [ 9539.813967] attempt to access beyond end of device
Mar 13 03:52:52 invisiblethings kernel: [ 9539.813970] sda2: rw=16, want=3, limit=2
Mar 13 03:52:52 invisiblethings kernel: [ 9539.813972] hfsplus: unable to find HFS+ superblock
Mar 13 03:52:52 invisiblethings kernel: [ 9539.815978] qnx4: no qnx4 filesystem (no root dir).
Mar 13 03:52:52 invisiblethings kernel: [ 9539.816980] ufs: You didn't specify the type of your ufs filesystem
Mar 13 03:52:52 invisiblethings kernel: [ 9539.816980]
Mar 13 03:52:52 invisiblethings kernel: [ 9539.816980] mount -t ufs -o ufstype=sun|sunx86|44bsd|ufs2|5xbsd|old|hp|nextstep|nextstep-cd|openstep ...
Mar 13 03:52:52 invisiblethings kernel: [ 9539.816980]
Mar 13 03:52:52 invisiblethings kernel: [ 9539.816980] >>>WARNING<<< Wrong ufstype may corrupt your filesystem, default is ufstype=old
Mar 13 03:52:52 invisiblethings kernel: [ 9539.818559] hfs: can't find a HFS filesystem on dev sda2
Mar 13 03:53:12 invisiblethings kernel: [ 9559.116280] audit: type=1400 audit(1457837592.238:26): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/sbin/dhclient" pid=8234 comm="apparmor_parser"
Mar 13 03:53:12 invisiblethings kernel: [ 9559.116586] audit: type=1400 audit(1457837592.238:27): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=8234 comm="apparmor_parser"
Mar 13 03:53:12 invisiblethings kernel: [ 9559.116793] audit: type=1400 audit(1457837592.238:28): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-helper" pid=8234 comm="apparmor_parser"
Mar 13 03:53:12 invisiblethings kernel: [ 9559.117434] audit: type=1400 audit(1457837592.242:29): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=8234 comm="apparmor_parser"
Mar 13 03:53:30 invisiblethings kernel: [ 9577.880732] EXT4-fs (sda2): unable to read superblock
Mar 13 03:53:30 invisiblethings kernel: [ 9577.881558] EXT4-fs (sda2): unable to read superblock
Mar 13 03:53:30 invisiblethings kernel: [ 9577.882349] EXT4-fs (sda2): unable to read superblock


dennissteins 14.03.2016 11:07

Kern.log Teil 2

Code:

Mar 13 03:53:30 invisiblethings kernel: [ 9577.883267] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:53:30 invisiblethings kernel: [ 9577.883269] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:53:31 invisiblethings kernel: [ 9577.886066] XFS (sda2): Invalid superblock magic number
Mar 13 03:53:31 invisiblethings kernel: [ 9577.888271] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:53:31 invisiblethings kernel: [ 9577.888274] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:53:31 invisiblethings kernel: [ 9577.890773] MINIX-fs: unable to read superblock
Mar 13 03:53:31 invisiblethings kernel: [ 9577.891609] attempt to access beyond end of device
Mar 13 03:53:31 invisiblethings kernel: [ 9577.891611] sda2: rw=16, want=3, limit=2
Mar 13 03:53:31 invisiblethings kernel: [ 9577.891612] hfsplus: unable to find HFS+ superblock
Mar 13 03:53:31 invisiblethings kernel: [ 9577.892520] qnx4: no qnx4 filesystem (no root dir).
Mar 13 03:53:31 invisiblethings kernel: [ 9577.893301] ufs: You didn't specify the type of your ufs filesystem
Mar 13 03:53:31 invisiblethings kernel: [ 9577.893301]
Mar 13 03:53:31 invisiblethings kernel: [ 9577.893301] mount -t ufs -o ufstype=sun|sunx86|44bsd|ufs2|5xbsd|old|hp|nextstep|nextstep-cd|openstep ...
Mar 13 03:53:31 invisiblethings kernel: [ 9577.893301]
Mar 13 03:53:31 invisiblethings kernel: [ 9577.893301] >>>WARNING<<< Wrong ufstype may corrupt your filesystem, default is ufstype=old
Mar 13 03:53:31 invisiblethings kernel: [ 9577.894822] hfs: can't find a HFS filesystem on dev sda2
Mar 13 03:53:36 invisiblethings kernel: [ 9583.000770] audit: type=1400 audit(1457837616.106:30): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/sbin/cups-browsed" pid=13719 comm="apparmor_parser"
Mar 13 03:53:53 invisiblethings kernel: [ 9600.830777] EXT4-fs (sda2): unable to read superblock
Mar 13 03:53:53 invisiblethings kernel: [ 9600.831645] EXT4-fs (sda2): unable to read superblock
Mar 13 03:53:53 invisiblethings kernel: [ 9600.832475] EXT4-fs (sda2): unable to read superblock
Mar 13 03:53:53 invisiblethings kernel: [ 9600.833372] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:53:53 invisiblethings kernel: [ 9600.833375] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:53:53 invisiblethings kernel: [ 9600.836161] XFS (sda2): Invalid superblock magic number
Mar 13 03:53:53 invisiblethings kernel: [ 9600.838277] FAT-fs (sda2): bogus number of reserved sectors
Mar 13 03:53:53 invisiblethings kernel: [ 9600.838280] FAT-fs (sda2): Can't find a valid FAT filesystem
Mar 13 03:53:53 invisiblethings kernel: [ 9600.841082] MINIX-fs: unable to read superblock
Mar 13 03:53:53 invisiblethings kernel: [ 9600.841927] attempt to access beyond end of device
Mar 13 03:53:53 invisiblethings kernel: [ 9600.841929] sda2: rw=16, want=3, limit=2
Mar 13 03:53:53 invisiblethings kernel: [ 9600.841931] hfsplus: unable to find HFS+ superblock
Mar 13 03:53:53 invisiblethings kernel: [ 9600.842913] qnx4: no qnx4 filesystem (no root dir).
Mar 13 03:53:53 invisiblethings kernel: [ 9600.843740] ufs: You didn't specify the type of your ufs filesystem
Mar 13 03:53:53 invisiblethings kernel: [ 9600.843740]
Mar 13 03:53:53 invisiblethings kernel: [ 9600.843740] mount -t ufs -o ufstype=sun|sunx86|44bsd|ufs2|5xbsd|old|hp|nextstep|nextstep-cd|openstep ...
Mar 13 03:53:53 invisiblethings kernel: [ 9600.843740]
Mar 13 03:53:53 invisiblethings kernel: [ 9600.843740] >>>WARNING<<< Wrong ufstype may corrupt your filesystem, default is ufstype=old
Mar 13 03:53:53 invisiblethings kernel: [ 9600.845245] hfs: can't find a HFS filesystem on dev sda2
Mar 13 03:55:21 invisiblethings kernel: [ 9688.489281] usb 1-9: new high-speed USB device number 4 using xhci_hcd
Mar 13 03:55:21 invisiblethings kernel: [ 9688.680154] usb 1-9: New USB device found, idVendor=058f, idProduct=6387
Mar 13 03:55:21 invisiblethings kernel: [ 9688.680157] usb 1-9: New USB device strings: Mfr=1, Product=2, SerialNumber=3
Mar 13 03:55:21 invisiblethings kernel: [ 9688.680158] usb 1-9: Product: Intenso Basic Line
Mar 13 03:55:21 invisiblethings kernel: [ 9688.680159] usb 1-9: Manufacturer: 6989
Mar 13 03:55:21 invisiblethings kernel: [ 9688.680160] usb 1-9: SerialNumber: A74EF26F
Mar 13 03:55:22 invisiblethings kernel: [ 9689.645925] usb-storage 1-9:1.0: USB Mass Storage device detected
Mar 13 03:55:22 invisiblethings kernel: [ 9689.646171] scsi host5: usb-storage 1-9:1.0
Mar 13 03:55:22 invisiblethings kernel: [ 9689.646244] usbcore: registered new interface driver usb-storage
Mar 13 03:55:22 invisiblethings kernel: [ 9689.799549] usbcore: registered new interface driver uas
Mar 13 03:55:23 invisiblethings kernel: [ 9690.648646] scsi 5:0:0:0: Direct-Access    Intenso  Basic Line      8.07 PQ: 0 ANSI: 4
Mar 13 03:55:23 invisiblethings kernel: [ 9690.648898] sd 5:0:0:0: Attached scsi generic sg2 type 0
Mar 13 03:55:23 invisiblethings kernel: [ 9690.650253] sd 5:0:0:0: [sdb] 31334400 512-byte logical blocks: (16.0 GB/14.9 GiB)
Mar 13 03:55:23 invisiblethings kernel: [ 9690.650891] sd 5:0:0:0: [sdb] Write Protect is off
Mar 13 03:55:23 invisiblethings kernel: [ 9690.650894] sd 5:0:0:0: [sdb] Mode Sense: 23 00 00 00
Mar 13 03:55:23 invisiblethings kernel: [ 9690.651544] sd 5:0:0:0: [sdb] Write cache: disabled, read cache: enabled, doesn't support DPO or FUA
Mar 13 03:55:23 invisiblethings kernel: [ 9690.655641]  sdb: sdb1
Mar 13 03:55:23 invisiblethings kernel: [ 9690.657595] sd 5:0:0:0: [sdb] Attached SCSI removable disk
Mar 13 03:55:25 invisiblethings kernel: [ 9692.300416] FAT-fs (sdb1): Volume was not properly unmounted. Some data may be corrupt. Please run fsck.
Mar 13 03:55:37 invisiblethings kernel: [ 9704.972300] audit: type=1400 audit(1457837737.978:31): apparmor="DENIED" operation="capable" profile="/usr/bin/evince-thumbnailer" pid=24321 comm="evince-thumbnai" capability=1  capname="dac_override"
Mar 13 03:55:37 invisiblethings kernel: [ 9704.972305] audit: type=1400 audit(1457837737.978:32): apparmor="DENIED" operation="capable" profile="/usr/bin/evince-thumbnailer" pid=24321 comm="evince-thumbnai" capability=2  capname="dac_read_search"
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuset
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpu
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuacct
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Linux version 4.2.0-30-generic (buildd@lgw01-60) (gcc version 5.2.1 20151010 (Ubuntu 5.2.1-22ubuntu2) ) #36-Ubuntu SMP Fri Feb 26 00:58:07 UTC 2016 (Ubuntu 4.2.0-30.36-generic 4.2.8-ckt3)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.2.0-30-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] KERNEL supported cpus:
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  Intel GenuineIntel
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  AMD AuthenticAMD
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  Centaur CentaurHauls
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x01: 'x87 floating point registers'
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x02: 'SSE registers'
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] x86/fpu: Enabled xstate features 0x3, context size is 0x240 bytes, using 'standard' format.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] x86/fpu: Using 'eager' FPU context switches.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: BIOS-provided physical RAM map:
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009d7ff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x000000000009d800-0x000000000009ffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000c8b3bfff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b3c000-0x00000000c8b42fff] ACPI NVS
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b43000-0x00000000c9601fff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c9602000-0x00000000c98c2fff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c98c3000-0x00000000dbaf6fff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbaf7000-0x00000000dbb5ffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb60000-0x00000000dbb89fff] ACPI data
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb8a000-0x00000000dbceffff] ACPI NVS
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbcf0000-0x00000000dbffefff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbfff000-0x00000000dbffffff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dd000000-0x00000000df1fffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000f8000000-0x00000000fbffffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed00000-0x00000000fed03fff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed1c000-0x00000000fed1ffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000ff000000-0x00000000ffffffff] reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fdfffff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] NX (Execute Disable) protection: active
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] SMBIOS 2.8 present.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] DMI: Hewlett-Packard HP 280 G1 MT/2B34, BIOS 80.14 09/28/2015
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: last_pfn = 0x11fe00 max_arch_pfn = 0x400000000
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] MTRR default type: uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] MTRR fixed ranges enabled:
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  00000-9FFFF write-back
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  A0000-BFFFF uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  C0000-CFFFF write-protect
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  D0000-E7FFF uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  E8000-FFFFF write-protect
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] MTRR variable ranges enabled:
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  0 base 0000000000 mask 7F00000000 write-back
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  1 base 0100000000 mask 7FE0000000 write-back
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  2 base 00E0000000 mask 7FE0000000 uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  3 base 00DE000000 mask 7FFE000000 uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  4 base 00DD000000 mask 7FFF000000 uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  5 base 011FE00000 mask 7FFFE00000 uncachable
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  6 disabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  7 disabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  8 disabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  9 disabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] x86/PAT: Configuration [0-7]: WB  WC  UC- UC  WB  WC  UC- WT 
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] original variable MTRRs
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 4GB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 1, base: 4GB, range: 512MB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 2, base: 3584MB, range: 512MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 3, base: 3552MB, range: 32MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 4, base: 3536MB, range: 16MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 5, base: 4606MB, range: 2MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] total RAM covered: 4046M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Found optimal setting for mtrr clean up
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  gran_size: 64K        chunk_size: 64M        num_reg: 7          lose cover RAM: 0G
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] New variable MTRRs
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 2GB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 1, base: 2GB, range: 1GB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 2, base: 3GB, range: 512MB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 3, base: 3536MB, range: 16MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 4, base: 3552MB, range: 32MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 5, base: 4GB, range: 512MB, type WB
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] reg 6, base: 4606MB, range: 2MB, type UC
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: update [mem 0xdd000000-0xffffffff] usable ==> reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: last_pfn = 0xdc000 max_arch_pfn = 0x400000000
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] found SMP MP-table at [mem 0x000fd7c0-0x000fd7cf] mapped at [ffff8800000fd7c0]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Scanning 1 areas for low memory corruption
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Base memory trampoline at [ffff880000097000] 97000 size 24576
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Using GB pages for direct mapping
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x00000000-0x000fffff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff1000, 0x01ff1fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff2000, 0x01ff2fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff3000, 0x01ff3fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x11fc00000-0x11fdfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x11fc00000-0x11fdfffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff4000, 0x01ff4fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x100000000-0x11fbfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x100000000-0x11fbfffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc0000000-0xc8b3bfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc0000000-0xc89fffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc8a00000-0xc8b3bfff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff5000, 0x01ff5fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] BRK [0x01ff6000, 0x01ff6fff] PGTABLE
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc8b43000-0xc9601fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc8b43000-0xc8bfffff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc8c00000-0xc95fffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc9600000-0xc9601fff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc98c3000-0xdbaf6fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc98c3000-0xc99fffff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xc9a00000-0xdb9fffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xdba00000-0xdbaf6fff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xdbfff000-0xdbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0xdbfff000-0xdbffffff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00100000-0xbfffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x00100000-0x001fffff] page 4k
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x00200000-0x3fffffff] page 2M
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [mem 0x40000000-0xbfffffff] page 1G
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] RAMDISK: [mem 0x33bd2000-0x35de0fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: Early table checksum verification disabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: RSDP 0x00000000000F0490 000024 (v02 HPQOEM)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: XSDT 0x00000000DBB69088 000094 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: FACP 0x00000000DBB81FA0 00010C (v05 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: DSDT 0x00000000DBB691B0 018DEC (v02 HPQOEM SLIC-CPC 00008014 INTL 20120711)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: FACS 0x00000000DBCEFF80 000040
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: APIC 0x00000000DBB820B0 000062 (v03 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: FPDT 0x00000000DBB82118 000044 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: FIDT 0x00000000DBB82160 00009C (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: TCPA 0x00000000DBB82200 000032 (v02 HPQOEM SLIC-CPC 00000001 MSFT 01000013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82238 000C7D (v02 HPQOEM SLIC-CPC 00001000 INTL 20120711)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82EB8 000539 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB833F8 000B74 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: MCFG 0x00000000DBB83F70 00003C (v01 HPQOEM SLIC-CPC 01072009 MSFT 00000097)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: HPET 0x00000000DBB83FB0 000038 (v01 HPQOEM SLIC-CPC 01072009 AMI. 00000005)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB83FE8 00036D (v01 HPQOEM SLIC-CPC 00001000 INTL 20120711)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB84358 005722 (v02 HPQOEM SLIC-CPC 00003000 INTL 20120711)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: UEFI 0x00000000DBB89A80 000042 (v01 HPQOEM SLIC-CPC 01072009      00000000)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: DBGP 0x00000000DBB89AC8 000034 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: Local APIC address 0xfee00000
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] No NUMA configuration found
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Faking a node at [mem 0x0000000000000000-0x000000011fdfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] NODE_DATA(0) allocated [mem 0x11fdf7000-0x11fdfbfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  [ffffea0000000000-ffffea00047fffff] PMD -> [ffff88011b400000-ffff88011f3fffff] on node 0
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Zone ranges:
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA      [mem 0x0000000000001000-0x0000000000ffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA32    [mem 0x0000000001000000-0x00000000ffffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  Normal  [mem 0x0000000100000000-0x000000011fdfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Movable zone start for each node
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Early memory node ranges
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000000001000-0x000000000009cfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000000100000-0x00000000c8b3bfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000c8b43000-0x00000000c9601fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000c98c3000-0x00000000dbaf6fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x00000000dbfff000-0x00000000dbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  node  0: [mem 0x0000000100000000-0x000000011fdfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Initmem setup node 0 [mem 0x0000000000001000-0x000000011fdfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] On node 0 totalpages: 1029580
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA zone: 64 pages used for memmap
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA zone: 21 pages reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA zone: 3996 pages, LIFO batch:0
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA32 zone: 13985 pages used for memmap
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  DMA32 zone: 895024 pages, LIFO batch:31
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  Normal zone: 2040 pages used for memmap
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]  Normal zone: 130560 pages, LIFO batch:31
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Reserving Intel graphics stolen memory at 0xdd200000-0xdf1fffff
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: PM-Timer IO Port: 0x1808
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: Local APIC address 0xfee00000
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] high edge lint[0x1])
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] IOAPIC[0]: apic_id 8, version 32, address 0xfec00000, GSI 0-23
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: IRQ0 used by override.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: IRQ9 used by override.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Using ACPI (MADT) for SMP configuration information
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] ACPI: HPET id: 0x8086a701 base: 0xfed00000
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] smpboot: Allowing 2 CPUs, 0 hotplug CPUs
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x00000000-0x00000fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x0009d000-0x0009dfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x0009e000-0x0009ffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x000a0000-0x000dffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0x000e0000-0x000fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xc8b3c000-0xc8b42fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xc9602000-0xc98c2fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbaf7000-0xdbb5ffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbb60000-0xdbb89fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbb8a000-0xdbceffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdbcf0000-0xdbffefff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdc000000-0xdcffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdd000000-0xdf1fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xdf200000-0xf7ffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xf8000000-0xfbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfc000000-0xfebfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfec00000-0xfec00fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfec01000-0xfecfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed00000-0xfed03fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed04000-0xfed1bfff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed1c000-0xfed1ffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfed20000-0xfedfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfee00000-0xfee00fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xfee01000-0xfeffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PM: Registered nosave memory: [mem 0xff000000-0xffffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] e820: [mem 0xdf200000-0xf7ffffff] available for PCI devices
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Booting paravirtualized kernel on bare hardware
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645519600211568 ns
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] setup_percpu: NR_CPUS:256 nr_cpumask_bits:256 nr_cpu_ids:2 nr_node_ids:1
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PERCPU: Embedded 33 pages/cpu @ffff88011fa00000 s96728 r8192 d30248 u1048576
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] pcpu-alloc: s96728 r8192 d30248 u1048576 alloc=1*2097152
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] pcpu-alloc: [0] 0 1
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages: 1013470
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Policy zone: Normal
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Kernel command line: BOOT_IMAGE=/vmlinuz-4.2.0-30-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Calgary: detecting Calgary via BIOS EBDA area
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Calgary: Unable to locate Rio Grande table in EBDA - bailing!
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Memory: 3934872K/4118320K available (8158K kernel code, 1238K rwdata, 3804K rodata, 1464K init, 1292K bss, 183448K reserved, 0K cma-reserved)
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Hierarchical RCU implementation.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]        Build-time adjustment of leaf fanout to 64.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]        RCU restricting CPUs from NR_CPUS=256 to nr_cpu_ids=2.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] RCU: Adjusting geometry for rcu_fanout_leaf=64, nr_cpu_ids=2
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] NR_IRQS:16640 nr_irqs:440 16
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]        Offload RCU callbacks from all CPUs
Mar 13 03:58:10 invisiblethings kernel: [    0.000000]        Offload RCU callbacks from CPUs: 0-1.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] spurious 8259A interrupt: IRQ7.
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] vt handoff: transparent VT on vt#7
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] Console: colour dummy device 80x25
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] console [tty0] enabled
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 133484882848 ns
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] hpet clockevent registered
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] tsc: Fast TSC calibration using PIT
Mar 13 03:58:10 invisiblethings kernel: [    0.000000] tsc: Detected 3192.570 MHz processor
Mar 13 03:58:10 invisiblethings kernel: [    0.000022] Calibrating delay loop (skipped), value calculated using timer frequency.. 6385.14 BogoMIPS (lpj=12770280)
Mar 13 03:58:10 invisiblethings kernel: [    0.000024] pid_max: default: 32768 minimum: 301
Mar 13 03:58:10 invisiblethings kernel: [    0.000028] ACPI: Core revision 20150619
Mar 13 03:58:10 invisiblethings kernel: [    0.014966] ACPI: All ACPI Tables successfully acquired
Mar 13 03:58:10 invisiblethings kernel: [    0.014981] Security Framework initialized
Mar 13 03:58:10 invisiblethings kernel: [    0.014989] AppArmor: AppArmor initialized
Mar 13 03:58:10 invisiblethings kernel: [    0.014989] Yama: becoming mindful.
Mar 13 03:58:10 invisiblethings kernel: [    0.015191] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.016231] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.016741] Mount-cache hash table entries: 8192 (order: 4, 65536 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.016746] Mountpoint-cache hash table entries: 8192 (order: 4, 65536 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.016919] Initializing cgroup subsys blkio
Mar 13 03:58:10 invisiblethings kernel: [    0.016922] Initializing cgroup subsys memory
Mar 13 03:58:10 invisiblethings kernel: [    0.016927] Initializing cgroup subsys devices
Mar 13 03:58:10 invisiblethings kernel: [    0.016928] Initializing cgroup subsys freezer
Mar 13 03:58:10 invisiblethings kernel: [    0.016930] Initializing cgroup subsys net_cls
Mar 13 03:58:10 invisiblethings kernel: [    0.016932] Initializing cgroup subsys perf_event
Mar 13 03:58:10 invisiblethings kernel: [    0.016933] Initializing cgroup subsys net_prio
Mar 13 03:58:10 invisiblethings kernel: [    0.016935] Initializing cgroup subsys hugetlb
Mar 13 03:58:10 invisiblethings kernel: [    0.016952] CPU: Physical Processor ID: 0
Mar 13 03:58:10 invisiblethings kernel: [    0.016953] CPU: Processor Core ID: 0
Mar 13 03:58:10 invisiblethings kernel: [    0.016956] ENERGY_PERF_BIAS: Set to 'normal', was 'performance'
Mar 13 03:58:10 invisiblethings kernel: [    0.016957] ENERGY_PERF_BIAS: View and update with x86_energy_perf_policy(8)
Mar 13 03:58:10 invisiblethings kernel: [    0.017712] mce: CPU supports 7 MCE banks
Mar 13 03:58:10 invisiblethings kernel: [    0.017721] CPU0: Thermal monitoring enabled (TM1)
Mar 13 03:58:10 invisiblethings kernel: [    0.017728] process: using mwait in idle threads
Mar 13 03:58:10 invisiblethings kernel: [    0.017730] Last level iTLB entries: 4KB 1024, 2MB 1024, 4MB 1024
Mar 13 03:58:10 invisiblethings kernel: [    0.017731] Last level dTLB entries: 4KB 1024, 2MB 1024, 4MB 1024, 1GB 4
Mar 13 03:58:10 invisiblethings kernel: [    0.018008] Freeing SMP alternatives memory: 28K (ffffffff81ea5000 - ffffffff81eac000)
Mar 13 03:58:10 invisiblethings kernel: [    0.019495] ftrace: allocating 30940 entries in 121 pages
Mar 13 03:58:10 invisiblethings kernel: [    0.029804] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=0 pin2=0
Mar 13 03:58:10 invisiblethings kernel: [    0.069524] TSC deadline timer enabled
Mar 13 03:58:10 invisiblethings kernel: [    0.069527] smpboot: CPU0: Intel(R) Pentium(R) CPU G3250 @ 3.20GHz (fam: 06, model: 3c, stepping: 03)
Mar 13 03:58:10 invisiblethings kernel: [    0.069547] Performance Events: PEBS fmt2+, 16-deep LBR, Haswell events, full-width counters, Intel PMU driver.
Mar 13 03:58:10 invisiblethings kernel: [    0.069562] ... version:                3
Mar 13 03:58:10 invisiblethings kernel: [    0.069563] ... bit width:              48
Mar 13 03:58:10 invisiblethings kernel: [    0.069563] ... generic registers:      8
Mar 13 03:58:10 invisiblethings kernel: [    0.069564] ... value mask:            0000ffffffffffff
Mar 13 03:58:10 invisiblethings kernel: [    0.069564] ... max period:            0000ffffffffffff
Mar 13 03:58:10 invisiblethings kernel: [    0.069565] ... fixed-purpose events:  3
Mar 13 03:58:10 invisiblethings kernel: [    0.069566] ... event mask:            00000007000000ff
Mar 13 03:58:10 invisiblethings kernel: [    0.070153] x86: Booting SMP configuration:
Mar 13 03:58:10 invisiblethings kernel: [    0.070154] .... node  #0, CPUs:      #1
Mar 13 03:58:10 invisiblethings kernel: [    0.074089] x86: Booted up 1 node, 2 CPUs
Mar 13 03:58:10 invisiblethings kernel: [    0.074092] smpboot: Total of 2 processors activated (12770.28 BogoMIPS)
Mar 13 03:58:10 invisiblethings kernel: [    0.074119] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
Mar 13 03:58:10 invisiblethings kernel: [    0.075493] devtmpfs: initialized
Mar 13 03:58:10 invisiblethings kernel: [    0.076828] evm: security.selinux
Mar 13 03:58:10 invisiblethings kernel: [    0.076829] evm: security.SMACK64
Mar 13 03:58:10 invisiblethings kernel: [    0.076830] evm: security.SMACK64EXEC
Mar 13 03:58:10 invisiblethings kernel: [    0.076830] evm: security.SMACK64TRANSMUTE
Mar 13 03:58:10 invisiblethings kernel: [    0.076831] evm: security.SMACK64MMAP
Mar 13 03:58:10 invisiblethings kernel: [    0.076831] evm: security.ima
Mar 13 03:58:10 invisiblethings kernel: [    0.076832] evm: security.capability
Mar 13 03:58:10 invisiblethings kernel: [    0.076871] PM: Registering ACPI NVS region [mem 0xc8b3c000-0xc8b42fff] (28672 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.076872] PM: Registering ACPI NVS region [mem 0xdbb8a000-0xdbceffff] (1466368 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.076931] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
Mar 13 03:58:10 invisiblethings kernel: [    0.076980] pinctrl core: initialized pinctrl subsystem
Mar 13 03:58:10 invisiblethings kernel: [    0.077063] RTC time:  2:56:56, date: 03/13/16
Mar 13 03:58:10 invisiblethings kernel: [    0.077144] NET: Registered protocol family 16
Mar 13 03:58:10 invisiblethings kernel: [    0.086115] cpuidle: using governor ladder
Mar 13 03:58:10 invisiblethings kernel: [    0.094127] cpuidle: using governor menu
Mar 13 03:58:10 invisiblethings kernel: [    0.094175] ACPI FADT declares the system doesn't support PCIe ASPM, so disable it
Mar 13 03:58:10 invisiblethings kernel: [    0.094176] ACPI: bus type PCI registered
Mar 13 03:58:10 invisiblethings kernel: [    0.094177] acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5
Mar 13 03:58:10 invisiblethings kernel: [    0.094224] PCI: MMCONFIG for domain 0000 [bus 00-3f] at [mem 0xf8000000-0xfbffffff] (base 0xf8000000)
Mar 13 03:58:10 invisiblethings kernel: [    0.094225] PCI: MMCONFIG at [mem 0xf8000000-0xfbffffff] reserved in E820
Mar 13 03:58:10 invisiblethings kernel: [    0.094232] PCI: Using configuration type 1 for base access
Mar 13 03:58:10 invisiblethings kernel: [    0.094367] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
Mar 13 03:58:10 invisiblethings kernel: [    0.094375] perf_event_intel: PMU erratum BJ122, BV98, HSD29 workaround disabled, HT off
Mar 13 03:58:10 invisiblethings kernel: [    0.102357] ACPI: Added _OSI(Module Device)
Mar 13 03:58:10 invisiblethings kernel: [    0.102358] ACPI: Added _OSI(Processor Device)
Mar 13 03:58:10 invisiblethings kernel: [    0.102359] ACPI: Added _OSI(3.0 _SCP Extensions)
Mar 13 03:58:10 invisiblethings kernel: [    0.102360] ACPI: Added _OSI(Processor Aggregator Device)
Mar 13 03:58:10 invisiblethings kernel: [    0.105960] ACPI: Executed 6 blocks of module-level executable AML code
Mar 13 03:58:10 invisiblethings kernel: [    0.110400] ACPI: Dynamic OEM Table Load:
Mar 13 03:58:10 invisiblethings kernel: [    0.110405] ACPI: SSDT 0xFFFF88011A5B9400 0003D3 (v02 HPQOEM SLIC-CPC 00003001 INTL 20051117)
Mar 13 03:58:10 invisiblethings kernel: [    0.110994] ACPI: Dynamic OEM Table Load:
Mar 13 03:58:10 invisiblethings kernel: [    0.110998] ACPI: SSDT 0xFFFF88011B016800 0005AA (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 03:58:10 invisiblethings kernel: [    0.111631] ACPI: Dynamic OEM Table Load:
Mar 13 03:58:10 invisiblethings kernel: [    0.111634] ACPI: SSDT 0xFFFF88011A5DB000 000119 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
Mar 13 03:58:10 invisiblethings kernel: [    0.112299] ACPI: Interpreter enabled
Mar 13 03:58:10 invisiblethings kernel: [    0.112306] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S1_] (20150619/hwxface-580)
Mar 13 03:58:10 invisiblethings kernel: [    0.112312] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S2_] (20150619/hwxface-580)
Mar 13 03:58:10 invisiblethings kernel: [    0.112329] ACPI: (supports S0 S3 S4 S5)
Mar 13 03:58:10 invisiblethings kernel: [    0.112330] ACPI: Using IOAPIC for interrupt routing
Mar 13 03:58:10 invisiblethings kernel: [    0.112353] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
Mar 13 03:58:10 invisiblethings kernel: [    0.112703] ACPI: Power Resource [PG00] (on)
Mar 13 03:58:10 invisiblethings kernel: [    0.112914] ACPI: Power Resource [PG01] (on)
Mar 13 03:58:10 invisiblethings kernel: [    0.113122] ACPI: Power Resource [PG02] (on)
Mar 13 03:58:10 invisiblethings kernel: [    0.115641] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.115829] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116018] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116221] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116404] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116589] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116771] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.116955] ACPI: Power Resource [WRST] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.119235] ACPI: Power Resource [FN00] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.119290] ACPI: Power Resource [FN01] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.119343] ACPI: Power Resource [FN02] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.119398] ACPI: Power Resource [FN03] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.119452] ACPI: Power Resource [FN04] (off)
Mar 13 03:58:10 invisiblethings kernel: [    0.120079] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-3e])
Mar 13 03:58:10 invisiblethings kernel: [    0.120084] acpi PNP0A08:00: _OSC: OS supports [ExtendedConfig ASPM ClockPM Segments MSI]
Mar 13 03:58:10 invisiblethings kernel: [    0.120582] acpi PNP0A08:00: _OSC: OS now controls [PCIeHotplug PME AER PCIeCapability]
Mar 13 03:58:10 invisiblethings kernel: [    0.120583] acpi PNP0A08:00: FADT indicates ASPM is unsupported, using BIOS configuration
Mar 13 03:58:10 invisiblethings kernel: [    0.120742] acpi PNP0A08:00: host bridge window expanded to [mem 0xdf200000-0xfeafffff window]; [mem 0xfe101000-0xfe113fff window] ignored
Mar 13 03:58:10 invisiblethings kernel: [    0.120878] PCI host bridge to bus 0000:00
Mar 13 03:58:10 invisiblethings kernel: [    0.120880] pci_bus 0000:00: root bus resource [bus 00-3e]
Mar 13 03:58:10 invisiblethings kernel: [    0.120881] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7 window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120882] pci_bus 0000:00: root bus resource [io  0x0d00-0xffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120884] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120885] pci_bus 0000:00: root bus resource [mem 0x000d0000-0x000d3fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120886] pci_bus 0000:00: root bus resource [mem 0x000d4000-0x000d7fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120887] pci_bus 0000:00: root bus resource [mem 0x000d8000-0x000dbfff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120888] pci_bus 0000:00: root bus resource [mem 0x000dc000-0x000dffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120890] pci_bus 0000:00: root bus resource [mem 0x000e0000-0x000e3fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120891] pci_bus 0000:00: root bus resource [mem 0x000e4000-0x000e7fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120892] pci_bus 0000:00: root bus resource [mem 0xdf200000-0xfeafffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.120898] pci 0000:00:00.0: [8086:0c00] type 00 class 0x060000
Mar 13 03:58:10 invisiblethings kernel: [    0.120961] pci 0000:00:01.0: [8086:0c01] type 01 class 0x060400
Mar 13 03:58:10 invisiblethings kernel: [    0.120985] pci 0000:00:01.0: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121036] pci 0000:00:01.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.121066] pci 0000:00:02.0: [8086:0402] type 00 class 0x030000
Mar 13 03:58:10 invisiblethings kernel: [    0.121073] pci 0000:00:02.0: reg 0x10: [mem 0xf7800000-0xf7bfffff 64bit]
Mar 13 03:58:10 invisiblethings kernel: [    0.121078] pci 0000:00:02.0: reg 0x18: [mem 0xe0000000-0xefffffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.121082] pci 0000:00:02.0: reg 0x20: [io  0xf000-0xf03f]
Mar 13 03:58:10 invisiblethings kernel: [    0.121169] pci 0000:00:14.0: [8086:8c31] type 00 class 0x0c0330
Mar 13 03:58:10 invisiblethings kernel: [    0.121186] pci 0000:00:14.0: reg 0x10: [mem 0xf7d00000-0xf7d0ffff 64bit]
Mar 13 03:58:10 invisiblethings kernel: [    0.121236] pci 0000:00:14.0: PME# supported from D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121269] pci 0000:00:14.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.121297] pci 0000:00:16.0: [8086:8c3a] type 00 class 0x078000
Mar 13 03:58:10 invisiblethings kernel: [    0.121313] pci 0000:00:16.0: reg 0x10: [mem 0xf7d15000-0xf7d1500f 64bit]
Mar 13 03:58:10 invisiblethings kernel: [    0.121366] pci 0000:00:16.0: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121445] pci 0000:00:1a.0: [8086:8c2d] type 00 class 0x0c0320
Mar 13 03:58:10 invisiblethings kernel: [    0.121461] pci 0000:00:1a.0: reg 0x10: [mem 0xf7d13000-0xf7d133ff]
Mar 13 03:58:10 invisiblethings kernel: [    0.121531] pci 0000:00:1a.0: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121565] pci 0000:00:1a.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.121594] pci 0000:00:1c.0: [8086:8c10] type 01 class 0x060400
Mar 13 03:58:10 invisiblethings kernel: [    0.121646] pci 0000:00:1c.0: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121704] pci 0000:00:1c.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.121734] pci 0000:00:1c.3: [8086:8c16] type 01 class 0x060400
Mar 13 03:58:10 invisiblethings kernel: [    0.121786] pci 0000:00:1c.3: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121843] pci 0000:00:1c.3: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.121875] pci 0000:00:1d.0: [8086:8c26] type 00 class 0x0c0320
Mar 13 03:58:10 invisiblethings kernel: [    0.121891] pci 0000:00:1d.0: reg 0x10: [mem 0xf7d12000-0xf7d123ff]
Mar 13 03:58:10 invisiblethings kernel: [    0.121962] pci 0000:00:1d.0: PME# supported from D0 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.121996] pci 0000:00:1d.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.122026] pci 0000:00:1f.0: [8086:8c5c] type 00 class 0x060100
Mar 13 03:58:10 invisiblethings kernel: [    0.122161] pci 0000:00:1f.2: [8086:8c02] type 00 class 0x010601
Mar 13 03:58:10 invisiblethings kernel: [    0.122173] pci 0000:00:1f.2: reg 0x10: [io  0xf0b0-0xf0b7]
Mar 13 03:58:10 invisiblethings kernel: [    0.122180] pci 0000:00:1f.2: reg 0x14: [io  0xf0a0-0xf0a3]
Mar 13 03:58:10 invisiblethings kernel: [    0.122186] pci 0000:00:1f.2: reg 0x18: [io  0xf090-0xf097]
Mar 13 03:58:10 invisiblethings kernel: [    0.122193] pci 0000:00:1f.2: reg 0x1c: [io  0xf080-0xf083]
Mar 13 03:58:10 invisiblethings kernel: [    0.122200] pci 0000:00:1f.2: reg 0x20: [io  0xf060-0xf07f]
Mar 13 03:58:10 invisiblethings kernel: [    0.122207] pci 0000:00:1f.2: reg 0x24: [mem 0xf7d11000-0xf7d117ff]
Mar 13 03:58:10 invisiblethings kernel: [    0.122234] pci 0000:00:1f.2: PME# supported from D3hot
Mar 13 03:58:10 invisiblethings kernel: [    0.122285] pci 0000:00:1f.3: [8086:8c22] type 00 class 0x0c0500
Mar 13 03:58:10 invisiblethings kernel: [    0.122299] pci 0000:00:1f.3: reg 0x10: [mem 0xf7d10000-0xf7d100ff 64bit]
Mar 13 03:58:10 invisiblethings kernel: [    0.122316] pci 0000:00:1f.3: reg 0x20: [io  0xf040-0xf05f]
Mar 13 03:58:10 invisiblethings kernel: [    0.122399] pci 0000:00:01.0: PCI bridge to [bus 01]
Mar 13 03:58:10 invisiblethings kernel: [    0.122448] pci 0000:00:1c.0: PCI bridge to [bus 02]
Mar 13 03:58:10 invisiblethings kernel: [    0.122512] pci 0000:03:00.0: [10ec:8168] type 00 class 0x020000
Mar 13 03:58:10 invisiblethings kernel: [    0.122530] pci 0000:03:00.0: reg 0x10: [io  0xe000-0xe0ff]
Mar 13 03:58:10 invisiblethings kernel: [    0.122557] pci 0000:03:00.0: reg 0x18: [mem 0xf7c00000-0xf7c00fff 64bit]
Mar 13 03:58:10 invisiblethings kernel: [    0.122573] pci 0000:03:00.0: reg 0x20: [mem 0xf0000000-0xf0003fff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.122648] pci 0000:03:00.0: supports D1 D2
Mar 13 03:58:10 invisiblethings kernel: [    0.122650] pci 0000:03:00.0: PME# supported from D0 D1 D2 D3hot D3cold
Mar 13 03:58:10 invisiblethings kernel: [    0.122694] pci 0000:03:00.0: System wakeup disabled by ACPI
Mar 13 03:58:10 invisiblethings kernel: [    0.130205] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 03:58:10 invisiblethings kernel: [    0.130208] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
Mar 13 03:58:10 invisiblethings kernel: [    0.130211] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.130216] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.130857] ACPI: PCI Interrupt Link [LNKA] (IRQs 3 4 5 6 10 *11 12 14 15)
Mar 13 03:58:10 invisiblethings kernel: [    0.130891] ACPI: PCI Interrupt Link [LNKB] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 03:58:10 invisiblethings kernel: [    0.130926] ACPI: PCI Interrupt Link [LNKC] (IRQs *3 4 5 6 10 11 12 14 15)
Mar 13 03:58:10 invisiblethings kernel: [    0.130958] ACPI: PCI Interrupt Link [LNKD] (IRQs 3 4 5 6 *10 11 12 14 15)
Mar 13 03:58:10 invisiblethings kernel: [    0.130989] ACPI: PCI Interrupt Link [LNKE] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 03:58:10 invisiblethings kernel: [    0.131020] ACPI: PCI Interrupt Link [LNKF] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 03:58:10 invisiblethings kernel: [    0.131052] ACPI: PCI Interrupt Link [LNKG] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 03:58:10 invisiblethings kernel: [    0.131084] ACPI: PCI Interrupt Link [LNKH] (IRQs 3 4 *5 6 10 11 12 14 15)
Mar 13 03:58:10 invisiblethings kernel: [    0.131290] ACPI: Enabled 6 GPEs in block 00 to 3F
Mar 13 03:58:10 invisiblethings kernel: [    0.131372] vgaarb: setting as boot device: PCI:0000:00:02.0
Mar 13 03:58:10 invisiblethings kernel: [    0.131374] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
Mar 13 03:58:10 invisiblethings kernel: [    0.131375] vgaarb: loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.131376] vgaarb: bridge control possible 0000:00:02.0
Mar 13 03:58:10 invisiblethings kernel: [    0.131531] SCSI subsystem initialized
Mar 13 03:58:10 invisiblethings kernel: [    0.131561] libata version 3.00 loaded.
Mar 13 03:58:10 invisiblethings kernel: [    0.131576] ACPI: bus type USB registered
Mar 13 03:58:10 invisiblethings kernel: [    0.131588] usbcore: registered new interface driver usbfs
Mar 13 03:58:10 invisiblethings kernel: [    0.131594] usbcore: registered new interface driver hub
Mar 13 03:58:10 invisiblethings kernel: [    0.131601] usbcore: registered new device driver usb
Mar 13 03:58:10 invisiblethings kernel: [    0.131693] PCI: Using ACPI for IRQ routing
Mar 13 03:58:10 invisiblethings kernel: [    0.132932] PCI: pci_cache_line_size set to 64 bytes
Mar 13 03:58:10 invisiblethings kernel: [    0.132960] e820: reserve RAM buffer [mem 0x0009d800-0x0009ffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.132961] e820: reserve RAM buffer [mem 0xc8b3c000-0xcbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.132962] e820: reserve RAM buffer [mem 0xc9602000-0xcbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.132963] e820: reserve RAM buffer [mem 0xdbaf7000-0xdbffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.132964] e820: reserve RAM buffer [mem 0x11fe00000-0x11fffffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.133046] NetLabel: Initializing
Mar 13 03:58:10 invisiblethings kernel: [    0.133047] NetLabel:  domain hash size = 128
Mar 13 03:58:10 invisiblethings kernel: [    0.133047] NetLabel:  protocols = UNLABELED CIPSOv4
Mar 13 03:58:10 invisiblethings kernel: [    0.133056] NetLabel:  unlabeled traffic allowed by default
Mar 13 03:58:10 invisiblethings kernel: [    0.133106] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0, 0, 0, 0, 0, 0
Mar 13 03:58:10 invisiblethings kernel: [    0.133110] hpet0: 8 comparators, 64-bit 14.318180 MHz counter
Mar 13 03:58:10 invisiblethings kernel: [    0.136136] clocksource: Switched to clocksource hpet
Mar 13 03:58:10 invisiblethings kernel: [    0.141401] AppArmor: AppArmor Filesystem Enabled
Mar 13 03:58:10 invisiblethings kernel: [    0.141464] pnp: PnP ACPI init
Mar 13 03:58:10 invisiblethings kernel: [    0.141634] system 00:00: [io  0x0800-0x087f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141637] system 00:00: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.141656] pnp 00:01: Plug and Play ACPI device, IDs PNP0b00 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.141680] system 00:02: [io  0x1854-0x1857] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141682] system 00:02: Plug and Play ACPI device, IDs INT3f0d PNP0c02 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.141819] system 00:03: [io  0x0a00-0x0a1f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141820] system 00:03: [io  0x0a20-0x0a2f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141821] system 00:03: [io  0x0a30-0x0a3f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141822] system 00:03: [io  0x0a40-0x0a7f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141823] system 00:03: [io  0x0a50-0x0a5f] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141825] system 00:03: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.141872] system 00:04: [io  0x04d0-0x04d1] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.141873] system 00:04: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.142000] pnp 00:05: Plug and Play ACPI device, IDs PNP0c31 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.142213] system 00:06: [mem 0xfed1c000-0xfed1ffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142215] system 00:06: [mem 0xfed10000-0xfed17fff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142216] system 00:06: [mem 0xfed18000-0xfed18fff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142217] system 00:06: [mem 0xfed19000-0xfed19fff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142219] system 00:06: [mem 0xf8000000-0xfbffffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142220] system 00:06: [mem 0xfed20000-0xfed3ffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142222] system 00:06: [mem 0xfed90000-0xfed93fff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142223] system 00:06: [mem 0xfed45000-0xfed8ffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142224] system 00:06: [mem 0xff000000-0xffffffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142226] system 00:06: [mem 0xfee00000-0xfeefffff] could not be reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142227] system 00:06: [mem 0xf7fe0000-0xf7feffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142228] system 00:06: [mem 0xf7ff0000-0xf7ffffff] has been reserved
Mar 13 03:58:10 invisiblethings kernel: [    0.142230] system 00:06: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 03:58:10 invisiblethings kernel: [    0.142372] pnp: PnP ACPI: found 7 devices
Mar 13 03:58:10 invisiblethings kernel: [    0.148231] clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns
Mar 13 03:58:10 invisiblethings kernel: [    0.148245] pci 0000:00:1c.0: bridge window [io  0x1000-0x0fff] to [bus 02] add_size 1000
Mar 13 03:58:10 invisiblethings kernel: [    0.148247] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff 64bit pref] to [bus 02] add_size 200000 add_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148248] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff] to [bus 02] add_size 200000 add_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148257] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x000fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148258] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x002fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148260] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x000fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148261] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x002fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 03:58:10 invisiblethings kernel: [    0.148262] pci 0000:00:1c.0: res[13]=[io  0x1000-0x0fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 03:58:10 invisiblethings kernel: [    0.148263] pci 0000:00:1c.0: res[13]=[io  0x1000-0x1fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 03:58:10 invisiblethings kernel: [    0.148268] pci 0000:00:1c.0: BAR 14: assigned [mem 0xdf200000-0xdf3fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148272] pci 0000:00:1c.0: BAR 15: assigned [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.148274] pci 0000:00:1c.0: BAR 13: assigned [io  0x2000-0x2fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148275] pci 0000:00:01.0: PCI bridge to [bus 01]
Mar 13 03:58:10 invisiblethings kernel: [    0.148280] pci 0000:00:1c.0: PCI bridge to [bus 02]
Mar 13 03:58:10 invisiblethings kernel: [    0.148283] pci 0000:00:1c.0:  bridge window [io  0x2000-0x2fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148287] pci 0000:00:1c.0:  bridge window [mem 0xdf200000-0xdf3fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148290] pci 0000:00:1c.0:  bridge window [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.148295] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 03:58:10 invisiblethings kernel: [    0.148298] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148302] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148305] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.148310] pci_bus 0000:00: resource 4 [io  0x0000-0x0cf7 window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148312] pci_bus 0000:00: resource 5 [io  0x0d00-0xffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148313] pci_bus 0000:00: resource 6 [mem 0x000a0000-0x000bffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148314] pci_bus 0000:00: resource 7 [mem 0x000d0000-0x000d3fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148315] pci_bus 0000:00: resource 8 [mem 0x000d4000-0x000d7fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148316] pci_bus 0000:00: resource 9 [mem 0x000d8000-0x000dbfff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148316] pci_bus 0000:00: resource 10 [mem 0x000dc000-0x000dffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148318] pci_bus 0000:00: resource 11 [mem 0x000e0000-0x000e3fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148318] pci_bus 0000:00: resource 12 [mem 0x000e4000-0x000e7fff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148319] pci_bus 0000:00: resource 13 [mem 0xdf200000-0xfeafffff window]
Mar 13 03:58:10 invisiblethings kernel: [    0.148321] pci_bus 0000:02: resource 0 [io  0x2000-0x2fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148322] pci_bus 0000:02: resource 1 [mem 0xdf200000-0xdf3fffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148323] pci_bus 0000:02: resource 2 [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.148324] pci_bus 0000:03: resource 0 [io  0xe000-0xefff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148325] pci_bus 0000:03: resource 1 [mem 0xf7c00000-0xf7cfffff]
Mar 13 03:58:10 invisiblethings kernel: [    0.148326] pci_bus 0000:03: resource 2 [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 03:58:10 invisiblethings kernel: [    0.148348] NET: Registered protocol family 2
Mar 13 03:58:10 invisiblethings kernel: [    0.148459] TCP established hash table entries: 32768 (order: 6, 262144 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.148538] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.148655] TCP: Hash tables configured (established 32768 bind 32768)
Mar 13 03:58:10 invisiblethings kernel: [    0.148676] UDP hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.148692] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.148733] NET: Registered protocol family 1
Mar 13 03:58:10 invisiblethings kernel: [    0.148745] pci 0000:00:02.0: Video device with shadowed ROM
Mar 13 03:58:10 invisiblethings kernel: [    0.188254] PCI: CLS 64 bytes, default 64
Mar 13 03:58:10 invisiblethings kernel: [    0.188296] Trying to unpack rootfs image as initramfs...
Mar 13 03:58:10 invisiblethings kernel: [    0.570372] Freeing initrd memory: 34876K (ffff880033bd2000 - ffff880035de1000)
Mar 13 03:58:10 invisiblethings kernel: [    0.570388] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
Mar 13 03:58:10 invisiblethings kernel: [    0.570390] software IO TLB [mem 0xd7af7000-0xdbaf7000] (64MB) mapped at [ffff8800d7af7000-ffff8800dbaf6fff]
Mar 13 03:58:10 invisiblethings kernel: [    0.570451] RAPL PMU detected, API unit is 2^-32 Joules, 4 fixed counters 655360 ms ovfl timer
Mar 13 03:58:10 invisiblethings kernel: [    0.570452] hw unit of domain pp0-core 2^-14 Joules
Mar 13 03:58:10 invisiblethings kernel: [    0.570453] hw unit of domain package 2^-14 Joules
Mar 13 03:58:10 invisiblethings kernel: [    0.570453] hw unit of domain dram 2^-14 Joules
Mar 13 03:58:10 invisiblethings kernel: [    0.570454] hw unit of domain pp1-gpu 2^-14 Joules
Mar 13 03:58:10 invisiblethings kernel: [    0.570550] microcode: CPU0 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 03:58:10 invisiblethings kernel: [    0.570554] microcode: CPU1 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 03:58:10 invisiblethings kernel: [    0.570596] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
Mar 13 03:58:10 invisiblethings kernel: [    0.570657] Scanning for low memory corruption every 60 seconds
Mar 13 03:58:10 invisiblethings kernel: [    0.570902] futex hash table entries: 512 (order: 3, 32768 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.570918] Initialise system trusted keyring
Mar 13 03:58:10 invisiblethings kernel: [    0.570936] audit: initializing netlink subsys (disabled)
Mar 13 03:58:10 invisiblethings kernel: [    0.570950] audit: type=2000 audit(1457837815.568:1): initialized
Mar 13 03:58:10 invisiblethings kernel: [    0.571214] HugeTLB registered 1 GB page size, pre-allocated 0 pages
Mar 13 03:58:10 invisiblethings kernel: [    0.571215] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mar 13 03:58:10 invisiblethings kernel: [    0.572220] zpool: loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.572221] zbud: loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.572346] VFS: Disk quotas dquot_6.6.0
Mar 13 03:58:10 invisiblethings kernel: [    0.572369] VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mar 13 03:58:10 invisiblethings kernel: [    0.572682] fuse init (API version 7.23)
Mar 13 03:58:10 invisiblethings kernel: [    0.572779] Key type big_key registered
Mar 13 03:58:10 invisiblethings kernel: [    0.573014] Key type asymmetric registered
Mar 13 03:58:10 invisiblethings kernel: [    0.573016] Asymmetric key parser 'x509' registered
Mar 13 03:58:10 invisiblethings kernel: [    0.573027] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 249)
Mar 13 03:58:10 invisiblethings kernel: [    0.573046] io scheduler noop registered
Mar 13 03:58:10 invisiblethings kernel: [    0.573048] io scheduler deadline registered (default)
Mar 13 03:58:10 invisiblethings kernel: [    0.573069] io scheduler cfq registered
Mar 13 03:58:10 invisiblethings kernel: [    0.573486] pcieport 0000:00:01.0: Signaling PME through PCIe PME interrupt
Mar 13 03:58:10 invisiblethings kernel: [    0.573489] pcie_pme 0000:00:01.0:pcie01: service driver pcie_pme loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.573504] pcieport 0000:00:1c.0: Signaling PME through PCIe PME interrupt
Mar 13 03:58:10 invisiblethings kernel: [    0.573507] pcie_pme 0000:00:1c.0:pcie01: service driver pcie_pme loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.573521] pcieport 0000:00:1c.3: Signaling PME through PCIe PME interrupt
Mar 13 03:58:10 invisiblethings kernel: [    0.573522] pci 0000:03:00.0: Signaling PME through PCIe PME interrupt
Mar 13 03:58:10 invisiblethings kernel: [    0.573526] pcie_pme 0000:00:1c.3:pcie01: service driver pcie_pme loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.573530] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
Mar 13 03:58:10 invisiblethings kernel: [    0.573540] pciehp 0000:00:1c.0:pcie04: Slot #0 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ LLActRep+
Mar 13 03:58:10 invisiblethings kernel: [    0.573557] pciehp 0000:00:1c.0:pcie04: service driver pciehp loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.573559] pciehp: PCI Express Hot Plug Controller Driver version: 0.4
Mar 13 03:58:10 invisiblethings kernel: [    0.573583] vesafb: mode is 1920x1080x32, linelength=7680, pages=0
Mar 13 03:58:10 invisiblethings kernel: [    0.573584] vesafb: scrolling: redraw
Mar 13 03:58:10 invisiblethings kernel: [    0.573585] vesafb: Truecolor: size=8:8:8:8, shift=24:16:8:0
Mar 13 03:58:10 invisiblethings kernel: [    0.573594] vesafb: framebuffer at 0xe0000000, mapped to 0xffffc90000800000, using 8128k, total 8128k
Mar 13 03:58:10 invisiblethings kernel: [    0.573670] Console: switching to colour frame buffer device 240x67
Mar 13 03:58:10 invisiblethings kernel: [    0.573686] fb0: VESA VGA frame buffer device
Mar 13 03:58:10 invisiblethings kernel: [    0.573698] intel_idle: MWAIT substates: 0x2120
Mar 13 03:58:10 invisiblethings kernel: [    0.573699] intel_idle: v0.4 model 0x3C
Mar 13 03:58:10 invisiblethings kernel: [    0.573699] intel_idle: lapic_timer_reliable_states 0xffffffff
Mar 13 03:58:10 invisiblethings kernel: [    0.573815] input: Power Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input0
Mar 13 03:58:10 invisiblethings kernel: [    0.573818] ACPI: Power Button [PWRB]
Mar 13 03:58:10 invisiblethings kernel: [    0.573842] input: Sleep Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1
Mar 13 03:58:10 invisiblethings kernel: [    0.573845] ACPI: Sleep Button [SLPB]
Mar 13 03:58:10 invisiblethings kernel: [    0.573869] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input2
Mar 13 03:58:10 invisiblethings kernel: [    0.573870] ACPI: Power Button [PWRF]
Mar 13 03:58:10 invisiblethings kernel: [    0.574359] thermal LNXTHERM:00: registered as thermal_zone0
Mar 13 03:58:10 invisiblethings kernel: [    0.574361] ACPI: Thermal Zone [TZ00] (28 C)
Mar 13 03:58:10 invisiblethings kernel: [    0.574484] thermal LNXTHERM:01: registered as thermal_zone1
Mar 13 03:58:10 invisiblethings kernel: [    0.574485] ACPI: Thermal Zone [TZ01] (30 C)
Mar 13 03:58:10 invisiblethings kernel: [    0.574526] GHES: HEST is not enabled!
Mar 13 03:58:10 invisiblethings kernel: [    0.574594] Serial: 8250/16550 driver, 32 ports, IRQ sharing enabled
Mar 13 03:58:10 invisiblethings kernel: [    0.575704] Linux agpgart interface v0.103
Mar 13 03:58:10 invisiblethings kernel: [    0.644602] tpm_tis 00:05: 1.2 TPM (device-id 0xB, rev-id 16)
Mar 13 03:58:10 invisiblethings kernel: [    0.946727] brd: module loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.947252] loop: module loaded
Mar 13 03:58:10 invisiblethings kernel: [    0.947379] libphy: Fixed MDIO Bus: probed
Mar 13 03:58:10 invisiblethings kernel: [    0.947382] tun: Universal TUN/TAP device driver, 1.6
Mar 13 03:58:10 invisiblethings kernel: [    0.947382] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Mar 13 03:58:10 invisiblethings kernel: [    0.947412] PPP generic driver version 2.4.2
Mar 13 03:58:10 invisiblethings kernel: [    0.947533] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.947538] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 1
Mar 13 03:58:10 invisiblethings kernel: [    0.948604] xhci_hcd 0000:00:14.0: hcc params 0x200077c1 hci version 0x100 quirks 0x00009810
Mar 13 03:58:10 invisiblethings kernel: [    0.948611] xhci_hcd 0000:00:14.0: cache line size of 64 is not supported
Mar 13 03:58:10 invisiblethings kernel: [    0.948675] usb usb1: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 03:58:10 invisiblethings kernel: [    0.948677] usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 03:58:10 invisiblethings kernel: [    0.948678] usb usb1: Product: xHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.948679] usb usb1: Manufacturer: Linux 4.2.0-30-generic xhci-hcd
Mar 13 03:58:10 invisiblethings kernel: [    0.948680] usb usb1: SerialNumber: 0000:00:14.0
Mar 13 03:58:10 invisiblethings kernel: [    0.948755] hub 1-0:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    0.948765] hub 1-0:1.0: 10 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    0.950401] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.950404] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 2
Mar 13 03:58:10 invisiblethings kernel: [    0.950425] usb usb2: New USB device found, idVendor=1d6b, idProduct=0003
Mar 13 03:58:10 invisiblethings kernel: [    0.950426] usb usb2: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 03:58:10 invisiblethings kernel: [    0.950427] usb usb2: Product: xHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.950428] usb usb2: Manufacturer: Linux 4.2.0-30-generic xhci-hcd
Mar 13 03:58:10 invisiblethings kernel: [    0.950428] usb usb2: SerialNumber: 0000:00:14.0
Mar 13 03:58:10 invisiblethings kernel: [    0.950492] hub 2-0:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    0.950496] hub 2-0:1.0: 2 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    0.950902] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mar 13 03:58:10 invisiblethings kernel: [    0.950906] ehci-pci: EHCI PCI platform driver
Mar 13 03:58:10 invisiblethings kernel: [    0.950967] ehci-pci 0000:00:1a.0: EHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.950970] ehci-pci 0000:00:1a.0: new USB bus registered, assigned bus number 3
Mar 13 03:58:10 invisiblethings kernel: [    0.950979] ehci-pci 0000:00:1a.0: debug port 2
Mar 13 03:58:10 invisiblethings kernel: [    0.954893] ehci-pci 0000:00:1a.0: cache line size of 64 is not supported
Mar 13 03:58:10 invisiblethings kernel: [    0.954899] ehci-pci 0000:00:1a.0: irq 16, io mem 0xf7d13000
Mar 13 03:58:10 invisiblethings kernel: [    0.968819] ehci-pci 0000:00:1a.0: USB 2.0 started, EHCI 1.00
Mar 13 03:58:10 invisiblethings kernel: [    0.968847] usb usb3: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 03:58:10 invisiblethings kernel: [    0.968849] usb usb3: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 03:58:10 invisiblethings kernel: [    0.968850] usb usb3: Product: EHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.968851] usb usb3: Manufacturer: Linux 4.2.0-30-generic ehci_hcd
Mar 13 03:58:10 invisiblethings kernel: [    0.968851] usb usb3: SerialNumber: 0000:00:1a.0
Mar 13 03:58:10 invisiblethings kernel: [    0.968971] hub 3-0:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    0.968975] hub 3-0:1.0: 2 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    0.969111] ehci-pci 0000:00:1d.0: EHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.969114] ehci-pci 0000:00:1d.0: new USB bus registered, assigned bus number 4
Mar 13 03:58:10 invisiblethings kernel: [    0.969124] ehci-pci 0000:00:1d.0: debug port 2
Mar 13 03:58:10 invisiblethings kernel: [    0.973036] ehci-pci 0000:00:1d.0: cache line size of 64 is not supported
Mar 13 03:58:10 invisiblethings kernel: [    0.973043] ehci-pci 0000:00:1d.0: irq 23, io mem 0xf7d12000
Mar 13 03:58:10 invisiblethings kernel: [    0.984866] ehci-pci 0000:00:1d.0: USB 2.0 started, EHCI 1.00
Mar 13 03:58:10 invisiblethings kernel: [    0.984896] usb usb4: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 03:58:10 invisiblethings kernel: [    0.984898] usb usb4: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 03:58:10 invisiblethings kernel: [    0.984899] usb usb4: Product: EHCI Host Controller
Mar 13 03:58:10 invisiblethings kernel: [    0.984899] usb usb4: Manufacturer: Linux 4.2.0-30-generic ehci_hcd
Mar 13 03:58:10 invisiblethings kernel: [    0.984900] usb usb4: SerialNumber: 0000:00:1d.0
Mar 13 03:58:10 invisiblethings kernel: [    0.985020] hub 4-0:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    0.985023] hub 4-0:1.0: 2 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    0.985103] ehci-platform: EHCI generic platform driver
Mar 13 03:58:10 invisiblethings kernel: [    0.985112] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mar 13 03:58:10 invisiblethings kernel: [    0.985115] ohci-pci: OHCI PCI platform driver
Mar 13 03:58:10 invisiblethings kernel: [    0.985122] ohci-platform: OHCI generic platform driver
Mar 13 03:58:10 invisiblethings kernel: [    0.985128] uhci_hcd: USB Universal Host Controller Interface driver
Mar 13 03:58:10 invisiblethings kernel: [    0.985161] i8042: PNP: No PS/2 controller found. Probing ports directly.
Mar 13 03:58:10 invisiblethings kernel: [    0.985565] serio: i8042 KBD port at 0x60,0x64 irq 1
Mar 13 03:58:10 invisiblethings kernel: [    0.985569] serio: i8042 AUX port at 0x60,0x64 irq 12
Mar 13 03:58:10 invisiblethings kernel: [    0.985796] mousedev: PS/2 mouse device common for all mice
Mar 13 03:58:10 invisiblethings kernel: [    0.985991] rtc_cmos 00:01: RTC can wake from S4
Mar 13 03:58:10 invisiblethings kernel: [    0.986107] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0
Mar 13 03:58:10 invisiblethings kernel: [    0.986129] rtc_cmos 00:01: alarms up to one month, y3k, 242 bytes nvram, hpet irqs
Mar 13 03:58:10 invisiblethings kernel: [    0.986135] i2c /dev entries driver
Mar 13 03:58:10 invisiblethings kernel: [    0.986186] device-mapper: uevent: version 1.0.3
Mar 13 03:58:10 invisiblethings kernel: [    0.986235] device-mapper: ioctl: 4.33.0-ioctl (2015-8-18) initialised: dm-devel@redhat.com
Mar 13 03:58:10 invisiblethings kernel: [    0.986249] Intel P-state driver initializing.
Mar 13 03:58:10 invisiblethings kernel: [    0.986345] ledtrig-cpu: registered to indicate activity on CPUs
Mar 13 03:58:10 invisiblethings kernel: [    0.986665] PCCT header not found.
Mar 13 03:58:10 invisiblethings kernel: [    0.987173] NET: Registered protocol family 10
Mar 13 03:58:10 invisiblethings kernel: [    0.987584] NET: Registered protocol family 17
Mar 13 03:58:10 invisiblethings kernel: [    0.987622] Key type dns_resolver registered
Mar 13 03:58:10 invisiblethings kernel: [    0.988364] Loading compiled-in X.509 certificates
Mar 13 03:58:10 invisiblethings kernel: [    0.990663] Loaded X.509 cert 'Build time autogenerated kernel key: aa46912a20e4e17b1e4a6ccc08bd3c70d4d8f464'
Mar 13 03:58:10 invisiblethings kernel: [    0.990692] registered taskstats version 1
Mar 13 03:58:10 invisiblethings kernel: [    0.990749] zswap: loading zswap
Mar 13 03:58:10 invisiblethings kernel: [    0.990753] zswap: using zbud pool
Mar 13 03:58:10 invisiblethings kernel: [    0.990763] zswap: using lzo compressor
Mar 13 03:58:10 invisiblethings kernel: [    0.993517] Key type trusted registered
Mar 13 03:58:10 invisiblethings kernel: [    0.995565] Key type encrypted registered
Mar 13 03:58:10 invisiblethings kernel: [    0.995570] AppArmor: AppArmor sha1 policy hashing enabled
Mar 13 03:58:10 invisiblethings kernel: [    1.261087] usb 1-1: new low-speed USB device number 2 using xhci_hcd
Mar 13 03:58:10 invisiblethings kernel: [    1.281103] usb 3-1: new high-speed USB device number 2 using ehci-pci
Mar 13 03:58:10 invisiblethings kernel: [    1.297115] usb 4-1: new high-speed USB device number 2 using ehci-pci
Mar 13 03:58:10 invisiblethings kernel: [    1.394391] usb 1-1: New USB device found, idVendor=0461, idProduct=0010
Mar 13 03:58:10 invisiblethings kernel: [    1.394393] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 03:58:10 invisiblethings kernel: [    1.394394] usb 1-1: Product: USB Keyboard
Mar 13 03:58:10 invisiblethings kernel: [    1.394395] usb 1-1: Manufacturer: NOVATEK
Mar 13 03:58:10 invisiblethings kernel: [    1.394463] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 03:58:10 invisiblethings kernel: [    1.394465] usb 1-1: ep 0x82 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 03:58:10 invisiblethings kernel: [    1.413612] usb 3-1: New USB device found, idVendor=8087, idProduct=8008
Mar 13 03:58:10 invisiblethings kernel: [    1.413614] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 03:58:10 invisiblethings kernel: [    1.413892] hub 3-1:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    1.413989] hub 3-1:1.0: 4 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    1.429604] usb 4-1: New USB device found, idVendor=8087, idProduct=8000
Mar 13 03:58:10 invisiblethings kernel: [    1.429606] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 03:58:10 invisiblethings kernel: [    1.429873] hub 4-1:1.0: USB hub found
Mar 13 03:58:10 invisiblethings kernel: [    1.429978] hub 4-1:1.0: 6 ports detected
Mar 13 03:58:10 invisiblethings kernel: [    1.561324] usb 1-2: new low-speed USB device number 3 using xhci_hcd
Mar 13 03:58:10 invisiblethings kernel: [    1.569338] tsc: Refined TSC clocksource calibration: 3192.607 MHz
Mar 13 03:58:10 invisiblethings kernel: [    1.569340] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x2e0501eb3d1, max_idle_ns: 440795254769 ns
Mar 13 03:58:10 invisiblethings kernel: [    1.692779] usb 1-2: New USB device found, idVendor=03f0, idProduct=094a
Mar 13 03:58:10 invisiblethings kernel: [    1.692781] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 03:58:10 invisiblethings kernel: [    1.692782] usb 1-2: Product: HP USB Optical Mouse
Mar 13 03:58:10 invisiblethings kernel: [    1.692783] usb 1-2: Manufacturer: PixArt
Mar 13 03:58:10 invisiblethings kernel: [    1.692901] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 03:58:10 invisiblethings kernel: [    1.701498] evm: HMAC attrs: 0x1
Mar 13 03:58:10 invisiblethings kernel: [    1.701824]  Magic number: 8:58:915
Mar 13 03:58:10 invisiblethings kernel: [    1.701929] rtc_cmos 00:01: setting system clock to 2016-03-13 02:56:57 UTC (1457837817)
Mar 13 03:58:10 invisiblethings kernel: [    1.701969] BIOS EDD facility v0.16 2004-Jun-25, 0 devices found
Mar 13 03:58:10 invisiblethings kernel: [    1.701969] EDD information not available.
Mar 13 03:58:10 invisiblethings kernel: [    1.702025] PM: Hibernation image not present or could not be loaded.
Mar 13 03:58:10 invisiblethings kernel: [    1.702310] Freeing unused kernel memory: 1464K (ffffffff81d37000 - ffffffff81ea5000)
Mar 13 03:58:10 invisiblethings kernel: [    1.702311] Write protecting the kernel read-only data: 12288k
Mar 13 03:58:10 invisiblethings kernel: [    1.702420] Freeing unused kernel memory: 20K (ffff8800017fb000 - ffff880001800000)
Mar 13 03:58:10 invisiblethings kernel: [    1.702487] Freeing unused kernel memory: 292K (ffff880001bb7000 - ffff880001c00000)
Mar 13 03:58:10 invisiblethings kernel: [    1.710008] random: systemd-udevd urandom read with 4 bits of entropy available
Mar 13 03:58:10 invisiblethings kernel: [    1.741004] [drm] Initialized drm 1.1.0 20060810
Mar 13 03:58:10 invisiblethings kernel: [    1.756309] wmi: Mapper loaded
Mar 13 03:58:10 invisiblethings kernel: [    1.757477] [drm] Memory usable by graphics device = 2048M
Mar 13 03:58:10 invisiblethings kernel: [    1.757480] checking generic (e0000000 7f0000) vs hw (e0000000 10000000)
Mar 13 03:58:10 invisiblethings kernel: [    1.757481] fb: switching to inteldrmfb from VESA VGA
Mar 13 03:58:10 invisiblethings kernel: [    1.757502] Console: switching to colour dummy device 80x25
Mar 13 03:58:10 invisiblethings kernel: [    1.757558] [drm] Replacing VGA console driver
Mar 13 03:58:10 invisiblethings kernel: [    1.760737] hidraw: raw HID events driver (C) Jiri Kosina
Mar 13 03:58:10 invisiblethings kernel: [    1.765044] r8169 Gigabit Ethernet driver 2.3LK-NAPI loaded
Mar 13 03:58:10 invisiblethings kernel: [    1.765052] r8169 0000:03:00.0: can't disable ASPM; OS doesn't have ASPM control
Mar 13 03:58:10 invisiblethings kernel: [    1.768663] [drm] Supports vblank timestamp caching Rev 2 (21.10.2013).
Mar 13 03:58:10 invisiblethings kernel: [    1.768665] [drm] Driver supports precise vblank timestamp query.
Mar 13 03:58:10 invisiblethings kernel: [    1.769056] vgaarb: device changed decodes: PCI:0000:00:02.0,olddecodes=io+mem,decodes=io+mem:owns=io+mem
Mar 13 03:58:10 invisiblethings kernel: [    1.770373] r8169 0000:03:00.0 eth0: RTL8168g/8111g at 0xffffc9000001e000, 48:0f:cf:36:52:2a, XID 0c000800 IRQ 29
Mar 13 03:58:10 invisiblethings kernel: [    1.770375] r8169 0000:03:00.0 eth0: jumbo features [frames: 9200 bytes, tx checksumming: ko]
Mar 13 03:58:10 invisiblethings kernel: [    1.774867] usbcore: registered new interface driver usbhid
Mar 13 03:58:10 invisiblethings kernel: [    1.774868] usbhid: USB HID core driver
Mar 13 03:58:10 invisiblethings kernel: [    1.784546] ACPI: Video Device [GFX0] (multi-head: yes  rom: no  post: no)
Mar 13 03:58:10 invisiblethings kernel: [    1.784693] input: Video Bus as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A08:00/LNXVIDEO:00/input/input6
Mar 13 03:58:10 invisiblethings kernel: [    1.784754] [drm] Initialized i915 1.6.0 20150522 for 0000:00:02.0 on minor 0
Mar 13 03:58:10 invisiblethings kernel: [    1.784774] ahci 0000:00:1f.2: version 3.0
Mar 13 03:58:10 invisiblethings kernel: [    1.784906] ahci 0000:00:1f.2: AHCI 0001.0300 32 slots 4 ports 6 Gbps 0x11 impl SATA mode
Mar 13 03:58:10 invisiblethings kernel: [    1.784908] ahci 0000:00:1f.2: flags: 64bit ncq pm led clo pio slum part ems
Mar 13 03:58:10 invisiblethings kernel: [    1.789894] scsi host0: ahci
Mar 13 03:58:10 invisiblethings kernel: [    1.789976] scsi host1: ahci
Mar 13 03:58:10 invisiblethings kernel: [    1.790042] scsi host2: ahci
Mar 13 03:58:10 invisiblethings kernel: [    1.790093] scsi host3: ahci
Mar 13 03:58:10 invisiblethings kernel: [    1.790142] scsi host4: ahci
Mar 13 03:58:10 invisiblethings kernel: [    1.790169] ata1: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11100 irq 30
Mar 13 03:58:10 invisiblethings kernel: [    1.790170] ata2: DUMMY
Mar 13 03:58:10 invisiblethings kernel: [    1.790171] ata3: DUMMY
Mar 13 03:58:10 invisiblethings kernel: [    1.790171] ata4: DUMMY
Mar 13 03:58:10 invisiblethings kernel: [    1.790173] ata5: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11300 irq 30
Mar 13 03:58:10 invisiblethings kernel: [    1.807461] fbcon: inteldrmfb (fb0) is primary device
Mar 13 03:58:10 invisiblethings kernel: [    1.807513] Console: switching to colour frame buffer device 240x67
Mar 13 03:58:10 invisiblethings kernel: [    1.807531] i915 0000:00:02.0: fb0: inteldrmfb frame buffer device
Mar 13 03:58:10 invisiblethings kernel: [    1.807532] i915 0000:00:02.0: registered panic notifier
Mar 13 03:58:10 invisiblethings kernel: [    1.820671] r8169 0000:03:00.0 enp3s0: renamed from eth0
Mar 13 03:58:10 invisiblethings kernel: [    1.829819] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:0461:0010.0001/input/input7
Mar 13 03:58:10 invisiblethings kernel: [    1.885738] hid-generic 0003:0461:0010.0001: input,hidraw0: USB HID v1.10 Keyboard [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input0
Mar 13 03:58:10 invisiblethings kernel: [    1.886544] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.1/0003:0461:0010.0002/input/input8
Mar 13 03:58:10 invisiblethings kernel: [    1.941772] hid-generic 0003:0461:0010.0002: input,hidraw1: USB HID v1.10 Device [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input1
Mar 13 03:58:10 invisiblethings kernel: [    1.941840] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:03F0:094A.0003/input/input9
Mar 13 03:58:10 invisiblethings kernel: [    1.941892] hid-generic 0003:03F0:094A.0003: input,hidraw2: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-2/input0
Mar 13 03:58:10 invisiblethings kernel: [    2.109781] ata1: SATA link up 6.0 Gbps (SStatus 133 SControl 300)
Mar 13 03:58:10 invisiblethings kernel: [    2.111081] ata1.00: ATA-8: WDC WD5000AAKX-60U6AA0, 18.01H18, max UDMA/100
Mar 13 03:58:10 invisiblethings kernel: [    2.111083] ata1.00: 976773168 sectors, multi 16: LBA48 NCQ (depth 31/32), AA
Mar 13 03:58:10 invisiblethings kernel: [    2.112246] ata1.00: configured for UDMA/100
Mar 13 03:58:10 invisiblethings kernel: [    2.112401] scsi 0:0:0:0: Direct-Access    ATA      WDC WD5000AAKX-6 1H18 PQ: 0 ANSI: 5
Mar 13 03:58:10 invisiblethings kernel: [    2.112625] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mar 13 03:58:10 invisiblethings kernel: [    2.112631] sd 0:0:0:0: [sda] 976773168 512-byte logical blocks: (500 GB/465 GiB)
Mar 13 03:58:10 invisiblethings kernel: [    2.112663] sd 0:0:0:0: [sda] Write Protect is off
Mar 13 03:58:10 invisiblethings kernel: [    2.112664] sd 0:0:0:0: [sda] Mode Sense: 00 3a 00 00
Mar 13 03:58:10 invisiblethings kernel: [    2.112676] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
Mar 13 03:58:10 invisiblethings kernel: [    2.113777] ata5: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
Mar 13 03:58:10 invisiblethings kernel: [    2.117004] ata5.00: ATAPI: hp      DVD A  DH16AFSH, DHH6, max UDMA/133
Mar 13 03:58:10 invisiblethings kernel: [    2.118021] ata5.00: configured for UDMA/133
Mar 13 03:58:10 invisiblethings kernel: [    2.120355] scsi 4:0:0:0: CD-ROM            hp      DVD A  DH16AFSH  DHH6 PQ: 0 ANSI: 5
Mar 13 03:58:10 invisiblethings kernel: [    2.128268]  sda: sda1 sda2 < sda5 >
Mar 13 03:58:10 invisiblethings kernel: [    2.128675] sd 0:0:0:0: [sda] Attached SCSI disk
Mar 13 03:58:10 invisiblethings kernel: [    2.139839] sr 4:0:0:0: [sr0] scsi3-mmc drive: 40x/40x writer dvd-ram cd/rw xa/form2 cdda tray
Mar 13 03:58:10 invisiblethings kernel: [    2.139842] cdrom: Uniform CD-ROM driver Revision: 3.20
Mar 13 03:58:10 invisiblethings kernel: [    2.139915] sr 4:0:0:0: Attached scsi CD-ROM sr0
Mar 13 03:58:10 invisiblethings kernel: [    2.139945] sr 4:0:0:0: Attached scsi generic sg1 type 5
Mar 13 03:58:10 invisiblethings kernel: [    2.570275] clocksource: Switched to clocksource tsc
Mar 13 03:58:10 invisiblethings kernel: [  36.921912] random: nonblocking pool is initialized
Mar 13 03:58:10 invisiblethings kernel: [  47.555967] NET: Registered protocol family 38
Mar 13 03:58:10 invisiblethings kernel: [  60.001561] EXT4-fs (dm-1): mounted filesystem with ordered data mode. Opts: (null)
Mar 13 03:58:10 invisiblethings kernel: [  62.055235] usb 1-2: USB disconnect, device number 3
Mar 13 03:58:10 invisiblethings kernel: [  62.244031] lp: driver loaded but no devices found
Mar 13 03:58:10 invisiblethings kernel: [  62.246257] ppdev: user-space parallel port driver
Mar 13 03:58:10 invisiblethings kernel: [  63.158618] EXT4-fs (dm-1): re-mounted. Opts: errors=remount-ro
Mar 13 03:58:10 invisiblethings kernel: [  63.530160] shpchp: Standard Hot Plug PCI Controller Driver version: 0.4
Mar 13 03:58:10 invisiblethings kernel: [  63.559316] usb 1-2: new low-speed USB device number 4 using xhci_hcd
Mar 13 03:58:10 invisiblethings kernel: [  63.690817] usb 1-2: New USB device found, idVendor=03f0, idProduct=094a
Mar 13 03:58:10 invisiblethings kernel: [  63.690820] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 03:58:10 invisiblethings kernel: [  63.690821] usb 1-2: Product: HP USB Optical Mouse
Mar 13 03:58:10 invisiblethings kernel: [  63.690822] usb 1-2: Manufacturer: PixArt
Mar 13 03:58:10 invisiblethings kernel: [  63.690889] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 03:58:10 invisiblethings kernel: [  63.693407] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:03F0:094A.0004/input/input10
Mar 13 03:58:10 invisiblethings kernel: [  63.693475] hid-generic 0003:03F0:094A.0004: input,hidraw2: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-2/input0
Mar 13 03:58:10 invisiblethings kernel: [  64.005564] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 03:58:10 invisiblethings kernel: [  64.005569] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005576] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005606] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 03:58:10 invisiblethings kernel: [  64.005609] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005612] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005634] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 03:58:10 invisiblethings kernel: [  64.005637] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005640] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005681] input: HP WMI hotkeys as /devices/virtual/input/input11
Mar 13 03:58:10 invisiblethings kernel: [  64.005774] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 03:58:10 invisiblethings kernel: [  64.005776] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005780] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005801] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 03:58:10 invisiblethings kernel: [  64.005803] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.005806] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 03:58:10 invisiblethings kernel: [  64.196183] kvm: disabled by bios
Mar 13 03:58:10 invisiblethings kernel: [  64.228427] kvm: disabled by bios
Mar 13 03:58:10 invisiblethings kernel: [  64.672693] intel_rapl: Found RAPL domain package
Mar 13 03:58:10 invisiblethings kernel: [  64.672695] intel_rapl: Found RAPL domain core
Mar 13 03:58:10 invisiblethings kernel: [  64.672696] intel_rapl: Found RAPL domain uncore
Mar 13 03:58:10 invisiblethings kernel: [  64.672697] intel_rapl: Found RAPL domain dram
Mar 13 03:58:10 invisiblethings kernel: [  64.672699] intel_rapl: RAPL package 0 domain package locked by BIOS
Mar 13 03:58:10 invisiblethings kernel: [  64.672701] intel_rapl: RAPL package 0 domain dram locked by BIOS
Mar 13 03:58:10 invisiblethings kernel: [  67.232775] EXT4-fs (sda1): mounting ext2 file system using the ext4 subsystem
Mar 13 03:58:10 invisiblethings kernel: [  67.286760] EXT4-fs (sda1): mounted filesystem without journal. Opts: (null)
Mar 13 03:58:10 invisiblethings kernel: [  70.882727] Adding 4115964k swap on /dev/mapper/cryptswap1.  Priority:-1 extents:1 across:4115964k FS
Mar 13 03:58:10 invisiblethings kernel: [  70.928096] audit: type=1400 audit(1457837886.663:2): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/lightdm/lightdm-guest-session" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  70.928102] audit: type=1400 audit(1457837886.663:3): apparmor="STATUS" operation="profile_load" profile="unconfined" name="chromium" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  70.979581] audit: type=1400 audit(1457837886.719:4): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/sbin/dhclient" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  70.979585] audit: type=1400 audit(1457837886.719:5): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  70.979588] audit: type=1400 audit(1457837886.719:6): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-helper" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  70.979591] audit: type=1400 audit(1457837886.719:7): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  71.022635] audit: type=1400 audit(1457837886.759:8): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  71.022642] audit: type=1400 audit(1457837886.759:9): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  71.022645] audit: type=1400 audit(1457837886.759:10): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince-previewer" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  71.022648] audit: type=1400 audit(1457837886.759:11): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=590 comm="apparmor_parser"
Mar 13 03:58:10 invisiblethings kernel: [  71.674959] cgroup: new mount options do not match the existing superblock, will be ignored
Mar 13 03:58:13 invisiblethings kernel: [  77.862865] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 03:58:13 invisiblethings kernel: [  78.065572] r8169 0000:03:00.0 enp3s0: link down
Mar 13 03:58:13 invisiblethings kernel: [  78.065591] r8169 0000:03:00.0 enp3s0: link down
Mar 13 03:58:13 invisiblethings kernel: [  78.065615] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 03:58:15 invisiblethings kernel: [  80.140562] r8169 0000:03:00.0 enp3s0: link up
Mar 13 03:58:15 invisiblethings kernel: [  80.140571] IPv6: ADDRCONF(NETDEV_CHANGE): enp3s0: link becomes ready
Mar 13 03:58:45 invisiblethings gnome-session[1450]: Entering running state
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuset
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpu
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Initializing cgroup subsys cpuacct
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Linux version 4.2.0-30-generic (buildd@lgw01-60) (gcc version 5.2.1 20151010 (Ubuntu 5.2.1-22ubuntu2) ) #36-Ubuntu SMP Fri Feb 26 00:58:07 UTC 2016 (Ubuntu 4.2.0-30.36-generic 4.2.8-ckt3)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.2.0-30-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] KERNEL supported cpus:
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  Intel GenuineIntel
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  AMD AuthenticAMD
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  Centaur CentaurHauls
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x01: 'x87 floating point registers'
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] x86/fpu: Supporting XSAVE feature 0x02: 'SSE registers'
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] x86/fpu: Enabled xstate features 0x3, context size is 0x240 bytes, using 'standard' format.
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] x86/fpu: Using 'eager' FPU context switches.
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: BIOS-provided physical RAM map:
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009d7ff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x000000000009d800-0x000000000009ffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000c8b3bfff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b3c000-0x00000000c8b42fff] ACPI NVS
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c8b43000-0x00000000c9601fff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c9602000-0x00000000c98c2fff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000c98c3000-0x00000000dbaf6fff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbaf7000-0x00000000dbb5ffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb60000-0x00000000dbb89fff] ACPI data
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbb8a000-0x00000000dbceffff] ACPI NVS
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbcf0000-0x00000000dbffefff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dbfff000-0x00000000dbffffff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000dd000000-0x00000000df1fffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000f8000000-0x00000000fbffffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed00000-0x00000000fed03fff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fed1c000-0x00000000fed1ffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x00000000ff000000-0x00000000ffffffff] reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fdfffff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] NX (Execute Disable) protection: active
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] SMBIOS 2.8 present.
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] DMI: Hewlett-Packard HP 280 G1 MT/2B34, BIOS 80.14 09/28/2015
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: last_pfn = 0x11fe00 max_arch_pfn = 0x400000000
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] MTRR default type: uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] MTRR fixed ranges enabled:
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  00000-9FFFF write-back
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  A0000-BFFFF uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  C0000-CFFFF write-protect
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  D0000-E7FFF uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  E8000-FFFFF write-protect
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] MTRR variable ranges enabled:
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  0 base 0000000000 mask 7F00000000 write-back
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  1 base 0100000000 mask 7FE0000000 write-back
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  2 base 00E0000000 mask 7FE0000000 uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  3 base 00DE000000 mask 7FFE000000 uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  4 base 00DD000000 mask 7FFF000000 uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  5 base 011FE00000 mask 7FFFE00000 uncachable
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  6 disabled
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  7 disabled
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  8 disabled
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  9 disabled
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] x86/PAT: Configuration [0-7]: WB  WC  UC- UC  WB  WC  UC- WT 
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] original variable MTRRs
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 4GB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 1, base: 4GB, range: 512MB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 2, base: 3584MB, range: 512MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 3, base: 3552MB, range: 32MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 4, base: 3536MB, range: 16MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 5, base: 4606MB, range: 2MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] total RAM covered: 4046M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Found optimal setting for mtrr clean up
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  gran_size: 64K        chunk_size: 64M        num_reg: 7          lose cover RAM: 0G
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] New variable MTRRs
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 0, base: 0GB, range: 2GB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 1, base: 2GB, range: 1GB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 2, base: 3GB, range: 512MB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 3, base: 3536MB, range: 16MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 4, base: 3552MB, range: 32MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 5, base: 4GB, range: 512MB, type WB
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] reg 6, base: 4606MB, range: 2MB, type UC
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: update [mem 0xdd000000-0xffffffff] usable ==> reserved
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] e820: last_pfn = 0xdc000 max_arch_pfn = 0x400000000
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] found SMP MP-table at [mem 0x000fd7c0-0x000fd7cf] mapped at [ffff8800000fd7c0]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Scanning 1 areas for low memory corruption
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Base memory trampoline at [ffff880000097000] 97000 size 24576
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] Using GB pages for direct mapping
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x00000000-0x000fffff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff1000, 0x01ff1fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff2000, 0x01ff2fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff3000, 0x01ff3fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x11fc00000-0x11fdfffff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x11fc00000-0x11fdfffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff4000, 0x01ff4fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x100000000-0x11fbfffff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x100000000-0x11fbfffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc0000000-0xc8b3bfff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc0000000-0xc89fffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc8a00000-0xc8b3bfff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff5000, 0x01ff5fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] BRK [0x01ff6000, 0x01ff6fff] PGTABLE
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc8b43000-0xc9601fff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc8b43000-0xc8bfffff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc8c00000-0xc95fffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc9600000-0xc9601fff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xc98c3000-0xdbaf6fff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc98c3000-0xc99fffff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xc9a00000-0xdb9fffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xdba00000-0xdbaf6fff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0xdbfff000-0xdbffffff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0xdbfff000-0xdbffffff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] init_memory_mapping: [mem 0x00100000-0xbfffffff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x00100000-0x001fffff] page 4k
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x00200000-0x3fffffff] page 2M
Mar 13 10:46:47 invisiblethings kernel: [    0.000000]  [mem 0x40000000-0xbfffffff] page 1G
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] RAMDISK: [mem 0x33bd2000-0x35de0fff]
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: Early table checksum verification disabled
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: RSDP 0x00000000000F0490 000024 (v02 HPQOEM)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: XSDT 0x00000000DBB69088 000094 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: FACP 0x00000000DBB81FA0 00010C (v05 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: DSDT 0x00000000DBB691B0 018DEC (v02 HPQOEM SLIC-CPC 00008014 INTL 20120711)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: FACS 0x00000000DBCEFF80 000040
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: APIC 0x00000000DBB820B0 000062 (v03 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: FPDT 0x00000000DBB82118 000044 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: FIDT 0x00000000DBB82160 00009C (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: TCPA 0x00000000DBB82200 000032 (v02 HPQOEM SLIC-CPC 00000001 MSFT 01000013)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82238 000C7D (v02 HPQOEM SLIC-CPC 00001000 INTL 20120711)
Mar 13 10:46:47 invisiblethings kernel: [    0.000000] ACPI: SSDT 0x00000000DBB82EB8 000539 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)


dennissteins 14.03.2016 11:15

Kern.log 3

Zitat:


ar 13 10:46:47 invisiblethings kernel: [ 0.122619] pci 0000:03:00.0: supports D1 D2
Mar 13 10:46:47 invisiblethings kernel: [ 0.122621] pci 0000:03:00.0: PME# supported from D0 D1 D2 D3hot D3cold
Mar 13 10:46:47 invisiblethings kernel: [ 0.122665] pci 0000:03:00.0: System wakeup disabled by ACPI
Mar 13 10:46:47 invisiblethings kernel: [ 0.130172] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 10:46:47 invisiblethings kernel: [ 0.130176] pci 0000:00:1c.3: bridge window [io 0xe000-0xefff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.130179] pci 0000:00:1c.3: bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.130184] pci 0000:00:1c.3: bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.130829] ACPI: PCI Interrupt Link [LNKA] (IRQs 3 4 5 6 10 *11 12 14 15)
Mar 13 10:46:47 invisiblethings kernel: [ 0.130863] ACPI: PCI Interrupt Link [LNKB] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 10:46:47 invisiblethings kernel: [ 0.130897] ACPI: PCI Interrupt Link [LNKC] (IRQs *3 4 5 6 10 11 12 14 15)
Mar 13 10:46:47 invisiblethings kernel: [ 0.130929] ACPI: PCI Interrupt Link [LNKD] (IRQs 3 4 5 6 *10 11 12 14 15)
Mar 13 10:46:47 invisiblethings kernel: [ 0.130961] ACPI: PCI Interrupt Link [LNKE] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 10:46:47 invisiblethings kernel: [ 0.130992] ACPI: PCI Interrupt Link [LNKF] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 10:46:47 invisiblethings kernel: [ 0.131024] ACPI: PCI Interrupt Link [LNKG] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
Mar 13 10:46:47 invisiblethings kernel: [ 0.131056] ACPI: PCI Interrupt Link [LNKH] (IRQs 3 4 *5 6 10 11 12 14 15)
Mar 13 10:46:47 invisiblethings kernel: [ 0.131263] ACPI: Enabled 6 GPEs in block 00 to 3F
Mar 13 10:46:47 invisiblethings kernel: [ 0.131347] vgaarb: setting as boot device: PCI:0000:00:02.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.131348] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
Mar 13 10:46:47 invisiblethings kernel: [ 0.131350] vgaarb: loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.131351] vgaarb: bridge control possible 0000:00:02.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.131504] SCSI subsystem initialized
Mar 13 10:46:47 invisiblethings kernel: [ 0.131534] libata version 3.00 loaded.
Mar 13 10:46:47 invisiblethings kernel: [ 0.131550] ACPI: bus type USB registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.131562] usbcore: registered new interface driver usbfs
Mar 13 10:46:47 invisiblethings kernel: [ 0.131569] usbcore: registered new interface driver hub
Mar 13 10:46:47 invisiblethings kernel: [ 0.131575] usbcore: registered new device driver usb
Mar 13 10:46:47 invisiblethings kernel: [ 0.131665] PCI: Using ACPI for IRQ routing
Mar 13 10:46:47 invisiblethings kernel: [ 0.132903] PCI: pci_cache_line_size set to 64 bytes
Mar 13 10:46:47 invisiblethings kernel: [ 0.132933] e820: reserve RAM buffer [mem 0x0009d800-0x0009ffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.132933] e820: reserve RAM buffer [mem 0xc8b3c000-0xcbffffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.132934] e820: reserve RAM buffer [mem 0xc9602000-0xcbffffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.132935] e820: reserve RAM buffer [mem 0xdbaf7000-0xdbffffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.132936] e820: reserve RAM buffer [mem 0x11fe00000-0x11fffffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.133019] NetLabel: Initializing
Mar 13 10:46:47 invisiblethings kernel: [ 0.133020] NetLabel: domain hash size = 128
Mar 13 10:46:47 invisiblethings kernel: [ 0.133020] NetLabel: protocols = UNLABELED CIPSOv4
Mar 13 10:46:47 invisiblethings kernel: [ 0.133029] NetLabel: unlabeled traffic allowed by default
Mar 13 10:46:47 invisiblethings kernel: [ 0.133080] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0, 0, 0, 0, 0, 0
Mar 13 10:46:47 invisiblethings kernel: [ 0.133083] hpet0: 8 comparators, 64-bit 14.318180 MHz counter
Mar 13 10:46:47 invisiblethings kernel: [ 0.135107] clocksource: Switched to clocksource hpet
Mar 13 10:46:47 invisiblethings kernel: [ 0.139603] AppArmor: AppArmor Filesystem Enabled
Mar 13 10:46:47 invisiblethings kernel: [ 0.139664] pnp: PnP ACPI init
Mar 13 10:46:47 invisiblethings kernel: [ 0.139837] system 00:00: [io 0x0800-0x087f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.139840] system 00:00: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.139859] pnp 00:01: Plug and Play ACPI device, IDs PNP0b00 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.139883] system 00:02: [io 0x1854-0x1857] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.139885] system 00:02: Plug and Play ACPI device, IDs INT3f0d PNP0c02 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.140150] system 00:03: [io 0x0a00-0x0a1f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140151] system 00:03: [io 0x0a20-0x0a2f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140152] system 00:03: [io 0x0a30-0x0a3f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140153] system 00:03: [io 0x0a40-0x0a7f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140154] system 00:03: [io 0x0a50-0x0a5f] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140156] system 00:03: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.140204] system 00:04: [io 0x04d0-0x04d1] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140206] system 00:04: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.140334] pnp 00:05: Plug and Play ACPI device, IDs PNP0c31 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.140544] system 00:06: [mem 0xfed1c000-0xfed1ffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140546] system 00:06: [mem 0xfed10000-0xfed17fff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140548] system 00:06: [mem 0xfed18000-0xfed18fff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140549] system 00:06: [mem 0xfed19000-0xfed19fff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140550] system 00:06: [mem 0xf8000000-0xfbffffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140551] system 00:06: [mem 0xfed20000-0xfed3ffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140553] system 00:06: [mem 0xfed90000-0xfed93fff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140554] system 00:06: [mem 0xfed45000-0xfed8ffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140555] system 00:06: [mem 0xff000000-0xffffffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140557] system 00:06: [mem 0xfee00000-0xfeefffff] could not be reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140558] system 00:06: [mem 0xf7fe0000-0xf7feffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140559] system 00:06: [mem 0xf7ff0000-0xf7ffffff] has been reserved
Mar 13 10:46:47 invisiblethings kernel: [ 0.140561] system 00:06: Plug and Play ACPI device, IDs PNP0c02 (active)
Mar 13 10:46:47 invisiblethings kernel: [ 0.140703] pnp: PnP ACPI: found 7 devices
Mar 13 10:46:47 invisiblethings kernel: [ 0.146569] clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns
Mar 13 10:46:47 invisiblethings kernel: [ 0.146584] pci 0000:00:1c.0: bridge window [io 0x1000-0x0fff] to [bus 02] add_size 1000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146585] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff 64bit pref] to [bus 02] add_size 200000 add_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146587] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff] to [bus 02] add_size 200000 add_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146595] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x000fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146596] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x002fffff] res_to_dev_res add_size 200000 min_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146597] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x000fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146599] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x002fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146600] pci 0000:00:1c.0: res[13]=[io 0x1000-0x0fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146601] pci 0000:00:1c.0: res[13]=[io 0x1000-0x1fff] res_to_dev_res add_size 1000 min_align 1000
Mar 13 10:46:47 invisiblethings kernel: [ 0.146605] pci 0000:00:1c.0: BAR 14: assigned [mem 0xdf200000-0xdf3fffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146610] pci 0000:00:1c.0: BAR 15: assigned [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146611] pci 0000:00:1c.0: BAR 13: assigned [io 0x2000-0x2fff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146613] pci 0000:00:01.0: PCI bridge to [bus 01]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146618] pci 0000:00:1c.0: PCI bridge to [bus 02]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146620] pci 0000:00:1c.0: bridge window [io 0x2000-0x2fff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146624] pci 0000:00:1c.0: bridge window [mem 0xdf200000-0xdf3fffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146628] pci 0000:00:1c.0: bridge window [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146633] pci 0000:00:1c.3: PCI bridge to [bus 03]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146635] pci 0000:00:1c.3: bridge window [io 0xe000-0xefff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146639] pci 0000:00:1c.3: bridge window [mem 0xf7c00000-0xf7cfffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146643] pci 0000:00:1c.3: bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146648] pci_bus 0000:00: resource 4 [io 0x0000-0x0cf7 window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146649] pci_bus 0000:00: resource 5 [io 0x0d00-0xffff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146650] pci_bus 0000:00: resource 6 [mem 0x000a0000-0x000bffff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146651] pci_bus 0000:00: resource 7 [mem 0x000d0000-0x000d3fff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146652] pci_bus 0000:00: resource 8 [mem 0x000d4000-0x000d7fff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146653] pci_bus 0000:00: resource 9 [mem 0x000d8000-0x000dbfff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146654] pci_bus 0000:00: resource 10 [mem 0x000dc000-0x000dffff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146655] pci_bus 0000:00: resource 11 [mem 0x000e0000-0x000e3fff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146656] pci_bus 0000:00: resource 12 [mem 0x000e4000-0x000e7fff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146657] pci_bus 0000:00: resource 13 [mem 0xdf200000-0xfeafffff window]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146658] pci_bus 0000:02: resource 0 [io 0x2000-0x2fff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146659] pci_bus 0000:02: resource 1 [mem 0xdf200000-0xdf3fffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146660] pci_bus 0000:02: resource 2 [mem 0xdf400000-0xdf5fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146661] pci_bus 0000:03: resource 0 [io 0xe000-0xefff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146662] pci_bus 0000:03: resource 1 [mem 0xf7c00000-0xf7cfffff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146663] pci_bus 0000:03: resource 2 [mem 0xf0000000-0xf00fffff 64bit pref]
Mar 13 10:46:47 invisiblethings kernel: [ 0.146685] NET: Registered protocol family 2
Mar 13 10:46:47 invisiblethings kernel: [ 0.146794] TCP established hash table entries: 32768 (order: 6, 262144 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.146873] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.146991] TCP: Hash tables configured (established 32768 bind 32768)
Mar 13 10:46:47 invisiblethings kernel: [ 0.147013] UDP hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.147029] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.147069] NET: Registered protocol family 1
Mar 13 10:46:47 invisiblethings kernel: [ 0.147082] pci 0000:00:02.0: Video device with shadowed ROM
Mar 13 10:46:47 invisiblethings kernel: [ 0.187224] PCI: CLS 64 bytes, default 64
Mar 13 10:46:47 invisiblethings kernel: [ 0.187268] Trying to unpack rootfs image as initramfs...
Mar 13 10:46:47 invisiblethings kernel: [ 0.569494] Freeing initrd memory: 34876K (ffff880033bd2000 - ffff880035de1000)
Mar 13 10:46:47 invisiblethings kernel: [ 0.569509] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
Mar 13 10:46:47 invisiblethings kernel: [ 0.569511] software IO TLB [mem 0xd7af7000-0xdbaf7000] (64MB) mapped at [ffff8800d7af7000-ffff8800dbaf6fff]
Mar 13 10:46:47 invisiblethings kernel: [ 0.569570] RAPL PMU detected, API unit is 2^-32 Joules, 4 fixed counters 655360 ms ovfl timer
Mar 13 10:46:47 invisiblethings kernel: [ 0.569571] hw unit of domain pp0-core 2^-14 Joules
Mar 13 10:46:47 invisiblethings kernel: [ 0.569572] hw unit of domain package 2^-14 Joules
Mar 13 10:46:47 invisiblethings kernel: [ 0.569573] hw unit of domain dram 2^-14 Joules
Mar 13 10:46:47 invisiblethings kernel: [ 0.569573] hw unit of domain pp1-gpu 2^-14 Joules
Mar 13 10:46:47 invisiblethings kernel: [ 0.569670] microcode: CPU0 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 10:46:47 invisiblethings kernel: [ 0.569674] microcode: CPU1 sig=0x306c3, pf=0x2, revision=0x1d
Mar 13 10:46:47 invisiblethings kernel: [ 0.569712] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
Mar 13 10:46:47 invisiblethings kernel: [ 0.569772] Scanning for low memory corruption every 60 seconds
Mar 13 10:46:47 invisiblethings kernel: [ 0.570015] futex hash table entries: 512 (order: 3, 32768 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.570030] Initialise system trusted keyring
Mar 13 10:46:47 invisiblethings kernel: [ 0.570048] audit: initializing netlink subsys (disabled)
Mar 13 10:46:47 invisiblethings kernel: [ 0.570062] audit: type=2000 audit(1457862310.568:1): initialized
Mar 13 10:46:47 invisiblethings kernel: [ 0.570321] HugeTLB registered 1 GB page size, pre-allocated 0 pages
Mar 13 10:46:47 invisiblethings kernel: [ 0.570323] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mar 13 10:46:47 invisiblethings kernel: [ 0.571329] zpool: loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.571330] zbud: loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.571455] VFS: Disk quotas dquot_6.6.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.571486] VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mar 13 10:46:47 invisiblethings kernel: [ 0.571787] fuse init (API version 7.23)
Mar 13 10:46:47 invisiblethings kernel: [ 0.571888] Key type big_key registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.572121] Key type asymmetric registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.572123] Asymmetric key parser 'x509' registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.572134] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 249)
Mar 13 10:46:47 invisiblethings kernel: [ 0.572153] io scheduler noop registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.572155] io scheduler deadline registered (default)
Mar 13 10:46:47 invisiblethings kernel: [ 0.572174] io scheduler cfq registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.572565] pcieport 0000:00:01.0: Signaling PME through PCIe PME interrupt
Mar 13 10:46:47 invisiblethings kernel: [ 0.572567] pcie_pme 0000:00:01.0:pcie01: service driver pcie_pme loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.572582] pcieport 0000:00:1c.0: Signaling PME through PCIe PME interrupt
Mar 13 10:46:47 invisiblethings kernel: [ 0.572585] pcie_pme 0000:00:1c.0:pcie01: service driver pcie_pme loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.572599] pcieport 0000:00:1c.3: Signaling PME through PCIe PME interrupt
Mar 13 10:46:47 invisiblethings kernel: [ 0.572600] pci 0000:03:00.0: Signaling PME through PCIe PME interrupt
Mar 13 10:46:47 invisiblethings kernel: [ 0.572604] pcie_pme 0000:00:1c.3:pcie01: service driver pcie_pme loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.572608] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
Mar 13 10:46:47 invisiblethings kernel: [ 0.572617] pciehp 0000:00:1c.0:pcie04: Slot #0 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ LLActRep+
Mar 13 10:46:47 invisiblethings kernel: [ 0.572633] pciehp 0000:00:1c.0:pcie04: service driver pciehp loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.572635] pciehp: PCI Express Hot Plug Controller Driver version: 0.4
Mar 13 10:46:47 invisiblethings kernel: [ 0.572658] vesafb: mode is 1920x1080x32, linelength=7680, pages=0
Mar 13 10:46:47 invisiblethings kernel: [ 0.572659] vesafb: scrolling: redraw
Mar 13 10:46:47 invisiblethings kernel: [ 0.572660] vesafb: Truecolor: size=8:8:8:8, shift=24:16:8:0
Mar 13 10:46:47 invisiblethings kernel: [ 0.572669] vesafb: framebuffer at 0xe0000000, mapped to 0xffffc90000800000, using 8128k, total 8128k
Mar 13 10:46:47 invisiblethings kernel: [ 0.572740] Console: switching to colour frame buffer device 240x67
Mar 13 10:46:47 invisiblethings kernel: [ 0.572756] fb0: VESA VGA frame buffer device
Mar 13 10:46:47 invisiblethings kernel: [ 0.572768] intel_idle: MWAIT substates: 0x2120
Mar 13 10:46:47 invisiblethings kernel: [ 0.572768] intel_idle: v0.4 model 0x3C
Mar 13 10:46:47 invisiblethings kernel: [ 0.572769] intel_idle: lapic_timer_reliable_states 0xffffffff
Mar 13 10:46:47 invisiblethings kernel: [ 0.572877] input: Power Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input0
Mar 13 10:46:47 invisiblethings kernel: [ 0.572880] ACPI: Power Button [PWRB]
Mar 13 10:46:47 invisiblethings kernel: [ 0.572902] input: Sleep Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1
Mar 13 10:46:47 invisiblethings kernel: [ 0.572904] ACPI: Sleep Button [SLPB]
Mar 13 10:46:47 invisiblethings kernel: [ 0.572925] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input2
Mar 13 10:46:47 invisiblethings kernel: [ 0.572926] ACPI: Power Button [PWRF]
Mar 13 10:46:47 invisiblethings kernel: [ 0.573399] thermal LNXTHERM:00: registered as thermal_zone0
Mar 13 10:46:47 invisiblethings kernel: [ 0.573400] ACPI: Thermal Zone [TZ00] (28 C)
Mar 13 10:46:47 invisiblethings kernel: [ 0.573523] thermal LNXTHERM:01: registered as thermal_zone1
Mar 13 10:46:47 invisiblethings kernel: [ 0.573524] ACPI: Thermal Zone [TZ01] (30 C)
Mar 13 10:46:47 invisiblethings kernel: [ 0.573561] GHES: HEST is not enabled!
Mar 13 10:46:47 invisiblethings kernel: [ 0.573624] Serial: 8250/16550 driver, 32 ports, IRQ sharing enabled
Mar 13 10:46:47 invisiblethings kernel: [ 0.574728] Linux agpgart interface v0.103
Mar 13 10:46:47 invisiblethings kernel: [ 0.635588] tpm_tis 00:05: 1.2 TPM (device-id 0xB, rev-id 16)
Mar 13 10:46:47 invisiblethings kernel: [ 0.937695] brd: module loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.938212] loop: module loaded
Mar 13 10:46:47 invisiblethings kernel: [ 0.938337] libphy: Fixed MDIO Bus: probed
Mar 13 10:46:47 invisiblethings kernel: [ 0.938340] tun: Universal TUN/TAP device driver, 1.6
Mar 13 10:46:47 invisiblethings kernel: [ 0.938340] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Mar 13 10:46:47 invisiblethings kernel: [ 0.938372] PPP generic driver version 2.4.2
Mar 13 10:46:47 invisiblethings kernel: [ 0.938492] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.938496] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 1
Mar 13 10:46:47 invisiblethings kernel: [ 0.939564] xhci_hcd 0000:00:14.0: hcc params 0x200077c1 hci version 0x100 quirks 0x00009810
Mar 13 10:46:47 invisiblethings kernel: [ 0.939570] xhci_hcd 0000:00:14.0: cache line size of 64 is not supported
Mar 13 10:46:47 invisiblethings kernel: [ 0.939632] usb usb1: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 10:46:47 invisiblethings kernel: [ 0.939633] usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 10:46:47 invisiblethings kernel: [ 0.939635] usb usb1: Product: xHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.939635] usb usb1: Manufacturer: Linux 4.2.0-30-generic xhci-hcd
Mar 13 10:46:47 invisiblethings kernel: [ 0.939636] usb usb1: SerialNumber: 0000:00:14.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.939710] hub 1-0:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 0.939720] hub 1-0:1.0: 10 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 0.941360] xhci_hcd 0000:00:14.0: xHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.941362] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 2
Mar 13 10:46:47 invisiblethings kernel: [ 0.941383] usb usb2: New USB device found, idVendor=1d6b, idProduct=0003
Mar 13 10:46:47 invisiblethings kernel: [ 0.941384] usb usb2: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 10:46:47 invisiblethings kernel: [ 0.941385] usb usb2: Product: xHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.941386] usb usb2: Manufacturer: Linux 4.2.0-30-generic xhci-hcd
Mar 13 10:46:47 invisiblethings kernel: [ 0.941387] usb usb2: SerialNumber: 0000:00:14.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.941451] hub 2-0:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 0.941455] hub 2-0:1.0: 2 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 0.941857] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.941861] ehci-pci: EHCI PCI platform driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.941921] ehci-pci 0000:00:1a.0: EHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.941924] ehci-pci 0000:00:1a.0: new USB bus registered, assigned bus number 3
Mar 13 10:46:47 invisiblethings kernel: [ 0.941933] ehci-pci 0000:00:1a.0: debug port 2
Mar 13 10:46:47 invisiblethings kernel: [ 0.945823] ehci-pci 0000:00:1a.0: cache line size of 64 is not supported
Mar 13 10:46:47 invisiblethings kernel: [ 0.945830] ehci-pci 0000:00:1a.0: irq 16, io mem 0xf7d13000
Mar 13 10:46:47 invisiblethings kernel: [ 0.959784] ehci-pci 0000:00:1a.0: USB 2.0 started, EHCI 1.00
Mar 13 10:46:47 invisiblethings kernel: [ 0.959812] usb usb3: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 10:46:47 invisiblethings kernel: [ 0.959814] usb usb3: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 10:46:47 invisiblethings kernel: [ 0.959814] usb usb3: Product: EHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.959815] usb usb3: Manufacturer: Linux 4.2.0-30-generic ehci_hcd
Mar 13 10:46:47 invisiblethings kernel: [ 0.959816] usb usb3: SerialNumber: 0000:00:1a.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.959937] hub 3-0:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 0.959941] hub 3-0:1.0: 2 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 0.960075] ehci-pci 0000:00:1d.0: EHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.960079] ehci-pci 0000:00:1d.0: new USB bus registered, assigned bus number 4
Mar 13 10:46:47 invisiblethings kernel: [ 0.960087] ehci-pci 0000:00:1d.0: debug port 2
Mar 13 10:46:47 invisiblethings kernel: [ 0.963997] ehci-pci 0000:00:1d.0: cache line size of 64 is not supported
Mar 13 10:46:47 invisiblethings kernel: [ 0.964004] ehci-pci 0000:00:1d.0: irq 23, io mem 0xf7d12000
Mar 13 10:46:47 invisiblethings kernel: [ 0.975829] ehci-pci 0000:00:1d.0: USB 2.0 started, EHCI 1.00
Mar 13 10:46:47 invisiblethings kernel: [ 0.975858] usb usb4: New USB device found, idVendor=1d6b, idProduct=0002
Mar 13 10:46:47 invisiblethings kernel: [ 0.975859] usb usb4: New USB device strings: Mfr=3, Product=2, SerialNumber=1
Mar 13 10:46:47 invisiblethings kernel: [ 0.975860] usb usb4: Product: EHCI Host Controller
Mar 13 10:46:47 invisiblethings kernel: [ 0.975861] usb usb4: Manufacturer: Linux 4.2.0-30-generic ehci_hcd
Mar 13 10:46:47 invisiblethings kernel: [ 0.975862] usb usb4: SerialNumber: 0000:00:1d.0
Mar 13 10:46:47 invisiblethings kernel: [ 0.975982] hub 4-0:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 0.975985] hub 4-0:1.0: 2 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 0.976062] ehci-platform: EHCI generic platform driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.976070] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.976073] ohci-pci: OHCI PCI platform driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.976080] ohci-platform: OHCI generic platform driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.976085] uhci_hcd: USB Universal Host Controller Interface driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.976117] i8042: PNP: No PS/2 controller found. Probing ports directly.
Mar 13 10:46:47 invisiblethings kernel: [ 0.976514] serio: i8042 KBD port at 0x60,0x64 irq 1
Mar 13 10:46:47 invisiblethings kernel: [ 0.976518] serio: i8042 AUX port at 0x60,0x64 irq 12
Mar 13 10:46:47 invisiblethings kernel: [ 0.976744] mousedev: PS/2 mouse device common for all mice
Mar 13 10:46:47 invisiblethings kernel: [ 0.976937] rtc_cmos 00:01: RTC can wake from S4
Mar 13 10:46:47 invisiblethings kernel: [ 0.977053] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0
Mar 13 10:46:47 invisiblethings kernel: [ 0.977076] rtc_cmos 00:01: alarms up to one month, y3k, 242 bytes nvram, hpet irqs
Mar 13 10:46:47 invisiblethings kernel: [ 0.977082] i2c /dev entries driver
Mar 13 10:46:47 invisiblethings kernel: [ 0.977132] device-mapper: uevent: version 1.0.3
Mar 13 10:46:47 invisiblethings kernel: [ 0.977181] device-mapper: ioctl: 4.33.0-ioctl (2015-8-18) initialised: dm-devel@redhat.com
Mar 13 10:46:47 invisiblethings kernel: [ 0.977195] Intel P-state driver initializing.
Mar 13 10:46:47 invisiblethings kernel: [ 0.977292] ledtrig-cpu: registered to indicate activity on CPUs
Mar 13 10:46:47 invisiblethings kernel: [ 0.977611] PCCT header not found.
Mar 13 10:46:47 invisiblethings kernel: [ 0.978118] NET: Registered protocol family 10
Mar 13 10:46:47 invisiblethings kernel: [ 0.978515] NET: Registered protocol family 17
Mar 13 10:46:47 invisiblethings kernel: [ 0.978552] Key type dns_resolver registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.979260] Loading compiled-in X.509 certificates
Mar 13 10:46:47 invisiblethings kernel: [ 0.981554] Loaded X.509 cert 'Build time autogenerated kernel key: aa46912a20e4e17b1e4a6ccc08bd3c70d4d8f464'
Mar 13 10:46:47 invisiblethings kernel: [ 0.981590] registered taskstats version 1
Mar 13 10:46:47 invisiblethings kernel: [ 0.981645] zswap: loading zswap
Mar 13 10:46:47 invisiblethings kernel: [ 0.981649] zswap: using zbud pool
Mar 13 10:46:47 invisiblethings kernel: [ 0.981659] zswap: using lzo compressor
Mar 13 10:46:47 invisiblethings kernel: [ 0.984474] Key type trusted registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.986531] Key type encrypted registered
Mar 13 10:46:47 invisiblethings kernel: [ 0.986536] AppArmor: AppArmor sha1 policy hashing enabled
Mar 13 10:46:47 invisiblethings kernel: [ 1.252053] usb 1-1: new low-speed USB device number 2 using xhci_hcd
Mar 13 10:46:47 invisiblethings kernel: [ 1.272068] usb 3-1: new high-speed USB device number 2 using ehci-pci
Mar 13 10:46:47 invisiblethings kernel: [ 1.288080] usb 4-1: new high-speed USB device number 2 using ehci-pci
Mar 13 10:46:47 invisiblethings kernel: [ 1.385507] usb 1-1: New USB device found, idVendor=0461, idProduct=0010
Mar 13 10:46:47 invisiblethings kernel: [ 1.385519] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 10:46:47 invisiblethings kernel: [ 1.385520] usb 1-1: Product: USB Keyboard
Mar 13 10:46:47 invisiblethings kernel: [ 1.385521] usb 1-1: Manufacturer: NOVATEK
Mar 13 10:46:47 invisiblethings kernel: [ 1.385659] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 10:46:47 invisiblethings kernel: [ 1.385662] usb 1-1: ep 0x82 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 10:46:47 invisiblethings kernel: [ 1.404542] usb 3-1: New USB device found, idVendor=8087, idProduct=8008
Mar 13 10:46:47 invisiblethings kernel: [ 1.404544] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 10:46:47 invisiblethings kernel: [ 1.404824] hub 3-1:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 1.404904] hub 3-1:1.0: 4 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 1.420556] usb 4-1: New USB device found, idVendor=8087, idProduct=8000
Mar 13 10:46:47 invisiblethings kernel: [ 1.420558] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
Mar 13 10:46:47 invisiblethings kernel: [ 1.420814] hub 4-1:1.0: USB hub found
Mar 13 10:46:47 invisiblethings kernel: [ 1.420890] hub 4-1:1.0: 6 ports detected
Mar 13 10:46:47 invisiblethings kernel: [ 1.552294] usb 1-2: new low-speed USB device number 3 using xhci_hcd
Mar 13 10:46:47 invisiblethings kernel: [ 1.568307] tsc: Refined TSC clocksource calibration: 3192.605 MHz
Mar 13 10:46:47 invisiblethings kernel: [ 1.568310] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x2e05005e26b, max_idle_ns: 440795310808 ns
Mar 13 10:46:47 invisiblethings kernel: [ 1.684056] usb 1-2: New USB device found, idVendor=03f0, idProduct=094a
Mar 13 10:46:47 invisiblethings kernel: [ 1.684058] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 10:46:47 invisiblethings kernel: [ 1.684060] usb 1-2: Product: HP USB Optical Mouse
Mar 13 10:46:47 invisiblethings kernel: [ 1.684061] usb 1-2: Manufacturer: PixArt
Mar 13 10:46:47 invisiblethings kernel: [ 1.684191] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 10:46:47 invisiblethings kernel: [ 1.704474] evm: HMAC attrs: 0x1
Mar 13 10:46:47 invisiblethings kernel: [ 1.704800] Magic number: 8:147:778
Mar 13 10:46:47 invisiblethings kernel: [ 1.704907] rtc_cmos 00:01: setting system clock to 2016-03-13 09:45:12 UTC (1457862312)
Mar 13 10:46:47 invisiblethings kernel: [ 1.704943] BIOS EDD facility v0.16 2004-Jun-25, 0 devices found
Mar 13 10:46:47 invisiblethings kernel: [ 1.704944] EDD information not available.
Mar 13 10:46:47 invisiblethings kernel: [ 1.705000] PM: Hibernation image not present or could not be loaded.
Mar 13 10:46:47 invisiblethings kernel: [ 1.705210] Freeing unused kernel memory: 1464K (ffffffff81d37000 - ffffffff81ea5000)
Mar 13 10:46:47 invisiblethings kernel: [ 1.705212] Write protecting the kernel read-only data: 12288k
Mar 13 10:46:47 invisiblethings kernel: [ 1.705319] Freeing unused kernel memory: 20K (ffff8800017fb000 - ffff880001800000)
Mar 13 10:46:47 invisiblethings kernel: [ 1.705372] Freeing unused kernel memory: 292K (ffff880001bb7000 - ffff880001c00000)
Mar 13 10:46:47 invisiblethings kernel: [ 1.713253] random: systemd-udevd urandom read with 4 bits of entropy available
Mar 13 10:46:47 invisiblethings kernel: [ 1.746541] [drm] Initialized drm 1.1.0 20060810
Mar 13 10:46:47 invisiblethings kernel: [ 1.758616] wmi: Mapper loaded
Mar 13 10:46:47 invisiblethings kernel: [ 1.762403] hidraw: raw HID events driver (C) Jiri Kosina
Mar 13 10:46:47 invisiblethings kernel: [ 1.763859] ahci 0000:00:1f.2: version 3.0
Mar 13 10:46:47 invisiblethings kernel: [ 1.764005] ahci 0000:00:1f.2: AHCI 0001.0300 32 slots 4 ports 6 Gbps 0x11 impl SATA mode
Mar 13 10:46:47 invisiblethings kernel: [ 1.764007] ahci 0000:00:1f.2: flags: 64bit ncq pm led clo pio slum part ems
Mar 13 10:46:47 invisiblethings kernel: [ 1.766745] r8169 Gigabit Ethernet driver 2.3LK-NAPI loaded
Mar 13 10:46:47 invisiblethings kernel: [ 1.766752] r8169 0000:03:00.0: can't disable ASPM; OS doesn't have ASPM control
Mar 13 10:46:47 invisiblethings kernel: [ 1.770568] scsi host0: ahci
Mar 13 10:46:47 invisiblethings kernel: [ 1.770640] scsi host1: ahci
Mar 13 10:46:47 invisiblethings kernel: [ 1.772481] scsi host2: ahci
Mar 13 10:46:47 invisiblethings kernel: [ 1.774899] r8169 0000:03:00.0 eth0: RTL8168g/8111g at 0xffffc9000001e000, 48:0f:cf:36:52:2a, XID 0c000800 IRQ 29
Mar 13 10:46:47 invisiblethings kernel: [ 1.774901] r8169 0000:03:00.0 eth0: jumbo features [frames: 9200 bytes, tx checksumming: ko]
Mar 13 10:46:47 invisiblethings kernel: [ 1.776155] scsi host3: ahci
Mar 13 10:46:47 invisiblethings kernel: [ 1.776261] usbcore: registered new interface driver usbhid
Mar 13 10:46:47 invisiblethings kernel: [ 1.776263] usbhid: USB HID core driver
Mar 13 10:46:47 invisiblethings kernel: [ 1.780455] scsi host4: ahci
Mar 13 10:46:47 invisiblethings kernel: [ 1.780498] ata1: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11100 irq 28
Mar 13 10:46:47 invisiblethings kernel: [ 1.780499] ata2: DUMMY
Mar 13 10:46:47 invisiblethings kernel: [ 1.780500] ata3: DUMMY
Mar 13 10:46:47 invisiblethings kernel: [ 1.780501] ata4: DUMMY
Mar 13 10:46:47 invisiblethings kernel: [ 1.780503] ata5: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11300 irq 28
Mar 13 10:46:47 invisiblethings kernel: [ 1.784695] [drm] Memory usable by graphics device = 2048M
Mar 13 10:46:47 invisiblethings kernel: [ 1.784697] checking generic (e0000000 7f0000) vs hw (e0000000 10000000)
Mar 13 10:46:47 invisiblethings kernel: [ 1.784698] fb: switching to inteldrmfb from VESA VGA
Mar 13 10:46:47 invisiblethings kernel: [ 1.784719] Console: switching to colour dummy device 80x25
Mar 13 10:46:47 invisiblethings kernel: [ 1.784756] [drm] Replacing VGA console driver
Mar 13 10:46:47 invisiblethings kernel: [ 1.790544] [drm] Supports vblank timestamp caching Rev 2 (21.10.2013).
Mar 13 10:46:47 invisiblethings kernel: [ 1.790546] [drm] Driver supports precise vblank timestamp query.
Mar 13 10:46:47 invisiblethings kernel: [ 1.790635] vgaarb: device changed decodes: PCI:0000:00:02.0,olddecodes=io+mem,decodes=io+mem:owns=io+mem
Mar 13 10:46:47 invisiblethings kernel: [ 1.797236] ACPI: Video Device [GFX0] (multi-head: yes rom: no post: no)
Mar 13 10:46:47 invisiblethings kernel: [ 1.797380] input: Video Bus as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A08:00/LNXVIDEO:00/input/input6
Mar 13 10:46:47 invisiblethings kernel: [ 1.797464] [drm] Initialized i915 1.6.0 20150522 for 0000:00:02.0 on minor 0
Mar 13 10:46:47 invisiblethings kernel: [ 1.820011] fbcon: inteldrmfb (fb0) is primary device
Mar 13 10:46:47 invisiblethings kernel: [ 1.820064] Console: switching to colour frame buffer device 240x67
Mar 13 10:46:47 invisiblethings kernel: [ 1.820083] i915 0000:00:02.0: fb0: inteldrmfb frame buffer device
Mar 13 10:46:47 invisiblethings kernel: [ 1.820084] i915 0000:00:02.0: registered panic notifier
Mar 13 10:46:47 invisiblethings kernel: [ 1.823525] r8169 0000:03:00.0 enp3s0: renamed from eth0
Mar 13 10:46:47 invisiblethings kernel: [ 1.828759] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:0461:0010.0001/input/input7
Mar 13 10:46:47 invisiblethings kernel: [ 1.884710] hid-generic 0003:0461:0010.0001: input,hidraw0: USB HID v1.10 Keyboard [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input0
Mar 13 10:46:47 invisiblethings kernel: [ 1.885601] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.1/0003:0461:0010.0002/input/input8
Mar 13 10:46:47 invisiblethings kernel: [ 1.940747] hid-generic 0003:0461:0010.0002: input,hidraw1: USB HID v1.10 Device [NOVATEK USB Keyboard] on usb-0000:00:14.0-1/input1
Mar 13 10:46:47 invisiblethings kernel: [ 1.940817] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:03F0:094A.0003/input/input9
Mar 13 10:46:47 invisiblethings kernel: [ 1.940865] hid-generic 0003:03F0:094A.0003: input,hidraw2: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-2/input0
Mar 13 10:46:47 invisiblethings kernel: [ 2.100746] ata1: SATA link up 6.0 Gbps (SStatus 133 SControl 300)
Mar 13 10:46:47 invisiblethings kernel: [ 2.101841] ata1.00: ATA-8: WDC WD5000AAKX-60U6AA0, 18.01H18, max UDMA/100
Mar 13 10:46:47 invisiblethings kernel: [ 2.101843] ata1.00: 976773168 sectors, multi 16: LBA48 NCQ (depth 31/32), AA
Mar 13 10:46:47 invisiblethings kernel: [ 2.103002] ata1.00: configured for UDMA/100
Mar 13 10:46:47 invisiblethings kernel: [ 2.103172] scsi 0:0:0:0: Direct-Access ATA WDC WD5000AAKX-6 1H18 PQ: 0 ANSI: 5
Mar 13 10:46:47 invisiblethings kernel: [ 2.103413] sd 0:0:0:0: [sda] 976773168 512-byte logical blocks: (500 GB/465 GiB)
Mar 13 10:46:47 invisiblethings kernel: [ 2.103442] sd 0:0:0:0: [sda] Write Protect is off
Mar 13 10:46:47 invisiblethings kernel: [ 2.103444] sd 0:0:0:0: [sda] Mode Sense: 00 3a 00 00
Mar 13 10:46:47 invisiblethings kernel: [ 2.103456] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
Mar 13 10:46:47 invisiblethings kernel: [ 2.103525] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mar 13 10:46:47 invisiblethings kernel: [ 2.104741] ata5: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
Mar 13 10:46:47 invisiblethings kernel: [ 2.107962] ata5.00: ATAPI: hp DVD A DH16AFSH, DHH6, max UDMA/133
Mar 13 10:46:47 invisiblethings kernel: [ 2.108980] ata5.00: configured for UDMA/133
Mar 13 10:46:47 invisiblethings kernel: [ 2.111254] scsi 4:0:0:0: CD-ROM hp DVD A DH16AFSH DHH6 PQ: 0 ANSI: 5
Mar 13 10:46:47 invisiblethings kernel: [ 2.111355] sda: sda1 sda2 < sda5 >
Mar 13 10:46:47 invisiblethings kernel: [ 2.111733] sd 0:0:0:0: [sda] Attached SCSI disk
Mar 13 10:46:47 invisiblethings kernel: [ 2.131984] sr 4:0:0:0: [sr0] scsi3-mmc drive: 40x/40x writer dvd-ram cd/rw xa/form2 cdda tray
Mar 13 10:46:47 invisiblethings kernel: [ 2.131987] cdrom: Uniform CD-ROM driver Revision: 3.20
Mar 13 10:46:47 invisiblethings kernel: [ 2.132063] sr 4:0:0:0: Attached scsi CD-ROM sr0
Mar 13 10:46:47 invisiblethings kernel: [ 2.132093] sr 4:0:0:0: Attached scsi generic sg1 type 5
Mar 13 10:46:47 invisiblethings kernel: [ 2.569247] clocksource: Switched to clocksource tsc
Mar 13 10:46:47 invisiblethings kernel: [ 59.066774] random: nonblocking pool is initialized
Mar 13 10:46:47 invisiblethings kernel: [ 61.822414] NET: Registered protocol family 38
Mar 13 10:46:47 invisiblethings kernel: [ 62.046183] usb 1-2: USB disconnect, device number 3
Mar 13 10:46:47 invisiblethings kernel: [ 63.550271] usb 1-2: new low-speed USB device number 4 using xhci_hcd
Mar 13 10:46:47 invisiblethings kernel: [ 63.681997] usb 1-2: New USB device found, idVendor=03f0, idProduct=094a
Mar 13 10:46:47 invisiblethings kernel: [ 63.681999] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
Mar 13 10:46:47 invisiblethings kernel: [ 63.682000] usb 1-2: Product: HP USB Optical Mouse
Mar 13 10:46:47 invisiblethings kernel: [ 63.682001] usb 1-2: Manufacturer: PixArt
Mar 13 10:46:47 invisiblethings kernel: [ 63.682147] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
Mar 13 10:46:47 invisiblethings kernel: [ 63.684061] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:03F0:094A.0004/input/input10
Mar 13 10:46:47 invisiblethings kernel: [ 63.684146] hid-generic 0003:03F0:094A.0004: input,hidraw2: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-2/input0
Mar 13 10:46:47 invisiblethings kernel: [ 74.361828] EXT4-fs (dm-1): mounted filesystem with ordered data mode. Opts: (null)
Mar 13 10:46:47 invisiblethings kernel: [ 76.529936] lp: driver loaded but no devices found
Mar 13 10:46:47 invisiblethings kernel: [ 76.562928] ppdev: user-space parallel port driver
Mar 13 10:46:47 invisiblethings kernel: [ 79.764274] EXT4-fs (dm-1): re-mounted. Opts: errors=remount-ro
Mar 13 10:46:47 invisiblethings kernel: [ 80.177029] shpchp: Standard Hot Plug PCI Controller Driver version: 0.4
Mar 13 10:46:47 invisiblethings kernel: [ 80.735099] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735105] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735112] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735147] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735149] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735153] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735178] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735180] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735183] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735229] input: HP WMI hotkeys as /devices/virtual/input/input11
Mar 13 10:46:47 invisiblethings kernel: [ 80.735327] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735329] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735333] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735355] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735357] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 80.735360] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Mar 13 10:46:47 invisiblethings kernel: [ 81.075911] kvm: disabled by bios
Mar 13 10:46:47 invisiblethings kernel: [ 81.096954] kvm: disabled by bios
Mar 13 10:46:47 invisiblethings kernel: [ 81.426897] intel_rapl: Found RAPL domain package
Mar 13 10:46:47 invisiblethings kernel: [ 81.426901] intel_rapl: Found RAPL domain core
Mar 13 10:46:47 invisiblethings kernel: [ 81.426902] intel_rapl: Found RAPL domain uncore
Mar 13 10:46:47 invisiblethings kernel: [ 81.426904] intel_rapl: Found RAPL domain dram
Mar 13 10:46:47 invisiblethings kernel: [ 81.426906] intel_rapl: RAPL package 0 domain package locked by BIOS
Mar 13 10:46:47 invisiblethings kernel: [ 81.426909] intel_rapl: RAPL package 0 domain dram locked by BIOS
Mar 13 10:46:47 invisiblethings kernel: [ 85.852978] EXT4-fs (sda1): mounting ext2 file system using the ext4 subsystem
Mar 13 10:46:47 invisiblethings kernel: [ 85.927955] EXT4-fs (sda1): mounted filesystem without journal. Opts: (null)
Mar 13 10:46:47 invisiblethings kernel: [ 88.808434] audit: type=1400 audit(1457862399.531:2): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/lightdm/lightdm-guest-session" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 88.808441] audit: type=1400 audit(1457862399.531:3): apparmor="STATUS" operation="profile_load" profile="unconfined" name="chromium" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.285294] audit: type=1400 audit(1457862400.007:4): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/sbin/dhclient" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.285298] audit: type=1400 audit(1457862400.007:5): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.285301] audit: type=1400 audit(1457862400.007:6): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-helper" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.285304] audit: type=1400 audit(1457862400.007:7): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.795310] audit: type=1400 audit(1457862400.511:8): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.795318] audit: type=1400 audit(1457862400.511:9): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.795321] audit: type=1400 audit(1457862400.511:10): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince-previewer" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 89.795324] audit: type=1400 audit(1457862400.511:11): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=579 comm="apparmor_parser"
Mar 13 10:46:47 invisiblethings kernel: [ 93.917186] Adding 4115964k swap on /dev/mapper/cryptswap1. Priority:-1 extents:1 across:4115964k FS
Mar 13 10:46:48 invisiblethings kernel: [ 97.311510] cgroup: new mount options do not match the existing superblock, will be ignored
Mar 13 10:46:49 invisiblethings kernel: [ 98.556872] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 10:46:49 invisiblethings kernel: [ 98.849245] r8169 0000:03:00.0 enp3s0: link down
Mar 13 10:46:49 invisiblethings kernel: [ 98.849280] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
Mar 13 10:47:47 invisiblethings gnome-session[1156]: Entering running state
Mar 13 10:47:57 invisiblethings kernel: [ 166.622952] r8169 0000:03:00.0 enp3s0: link up
Mar 13 10:47:57 invisiblethings kernel: [ 166.622967] IPv6: ADDRCONF(NETDEV_CHANGE): enp3s0: link becomes ready
Mar 13 10:50:13 invisiblethings kernel: [ 303.237097] ip_tables: (C) 2000-2006 Netfilter Core Team
Mar 13 10:50:32 invisiblethings kernel: [ 322.208247] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
Mar 13 10:50:32 invisiblethings kernel: [ 322.265302] ip6_tables: (C) 2000-2006 Netfilter Core Team

iceweasel 15.03.2016 09:45

Also ich habe in deinen Linux-Auszügen keine Auffälligkeiten gefunden. Vielleicht kannst du mal das rauskopieren, was du als auffällig ansiehst. Die Meldungen z.B. unter Tiger sind ziemlich normal. Auch AppArmor meckert gerne mal rum. Und wenn deine Fritzbox von innen angegriffen wird dann wohl eher von der Malware auf deinem Windows-Rechner.

Daher:
- falls die Malware tatsächlich im BIOS verankert ist dort entsprechend bereinigen oder nur noch Linux nutzen
- alle Passwörter ändern
- Fritzbox zurücksetzen und neues Passwort vergeben
- Windows neu installieren

dennissteins 15.03.2016 10:08

Super, vielen Dank!

Firmware-Test: fwts
Habe der Übersichtlichkeit wegen den Log gekürzt und nach Fehlermeldungen selektiert


Code:

syntaxcheck: Re-assemble DSDT and SSDTs to find syntax errors and warnings.
--------------------------------------------------------------------------------
Test 1 of 1: Disassemble and reassemble DSDT and SSDTs.

Checking ACPI table DSDT (#0)

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 6740
Line | AML source
--------------------------------------------------------------------------------
06737|                }
06738|            }
06739|
06740|            Zero
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_ZERO 
06741|            Zero
06742|            Zero
06743|            Zero
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 10817
Line | AML source
--------------------------------------------------------------------------------
10814|        {
10815|            Return (MDBG) /* External reference */
10816|            Arg0
10817|        }
    |        ^
    | Error 6126: syntax error, unexpected '}' 
10818|
10819|        Return (Zero)
10820|    }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 20852
Line | AML source
--------------------------------------------------------------------------------
20849|                /* 1458 */  0x5D, 0x82, 0x06, 0xC3, 0x47, 0xE7, 0xC1, 0x60,  /* ]...G..` */
20850|                /* 1460 */  0xEE, 0x47, 0x1E, 0x9D, 0x00, 0x35, 0x16, 0x9E,  /* .G...5.. */
20851|                /* 1468 */  0x8A, 0x44, 0x47, 0x6E, 0x9F, 0xAE, 0xDE, 0xAE,  /* .DGn.... */
20852|                /* 1470 */  0x7C, 0x59, 0xF0, 0x85, 0xC1, 0x17, 0x2A, 0x2F,  /* |Y....*/ */
    |                                                                                        ^
    | Error 6126: syntax error, unexpected PARSEOP_EXP_MULTIPLY, expecting '}' 
20853|                /* 1478 */  0xE0, 0xC1, 0x1B, 0xC6, 0xF9, 0xC8, 0x87, 0x2A,  /* .......* */
20854|                /* 1480 */  0xFF, 0xFF, 0xA1, 0xE2, 0x04, 0x7E, 0x25, 0x78,  /* .....~%x */
20855|                /* 1488 */  0xD7, 0x0A, 0x11, 0xCC, 0xB0, 0x8F, 0x01, 0x8F,  /* ........ */
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 21193
Line | AML source
--------------------------------------------------------------------------------
21190|        Method (GBFE, 3, NotSerialized)
21191|        {
21192|            CreateByteField (Arg0, Arg1, TIDX)
21193|            Store (TIDX, Arg2)
    |                ^
    | Error 6126: syntax error, unexpected PARSEOP_STORE 
21194|        }
21195|
21196|        Method (PBFE, 3, NotSerialized)
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 25106
Line | AML source
--------------------------------------------------------------------------------
25103|    }
25104| }
25105|
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] SyntaxCheckIASLCompilerAborted: Test 1, Compilation aborted early
due to a parser detected syntax error.

ADVICE: Some subsequent errors may not be detected because the compiler had to
terminate prematurely. If the compiler did not abort early then potentially
correct code may parse incorrectly producing some or many false positive errors.

Table DSDT (0) reassembly: Found 5 errors, 0 warnings, 0 remarks.


Checking ACPI table SSDT (#1)

PASSED: Test 1, SSDT (1) reassembly, Found 0 errors, 0 warnings, 0 remarks.


Checking ACPI table SSDT (#2)

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 223
Line | AML source
--------------------------------------------------------------------------------
00220|                0x00000800
00221|            }
00222|        })
00223|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00224|        {
00225|            0x80000000,
00226|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 243
Line | AML source
--------------------------------------------------------------------------------
00240|            0x80000000
00241|        }
00242|
00243|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00244|        {
00245|            0x80000000,
00246|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 244
Line | AML source
--------------------------------------------------------------------------------
00241|        }
00242|
00243|        Package (0x06)
00244|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00245|            0x80000000,
00246|            0x80000000,
00247|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 263
Line | AML source
--------------------------------------------------------------------------------
00260|            0x80000000
00261|        }
00262|
00263|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00264|        {
00265|            0x80000000,
00266|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 264
Line | AML source
--------------------------------------------------------------------------------
00261|        }
00262|
00263|        Package (0x06)
00264|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00265|            0x80000000,
00266|            0x80000000,
00267|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 283
Line | AML source
--------------------------------------------------------------------------------
00280|            0x80000000
00281|        }
00282|
00283|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00284|        {
00285|            0x80000000,
00286|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 284
Line | AML source
--------------------------------------------------------------------------------
00281|        }
00282|
00283|        Package (0x06)
00284|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00285|            0x80000000,
00286|            0x80000000,
00287|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 303
Line | AML source
--------------------------------------------------------------------------------
00300|            0x80000000
00301|        }
00302|
00303|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00304|        {
00305|            0x80000000,
00306|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 304
Line | AML source
--------------------------------------------------------------------------------
00301|        }
00302|
00303|        Package (0x06)
00304|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00305|            0x80000000,
00306|            0x80000000,
00307|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 323
Line | AML source
--------------------------------------------------------------------------------
00320|            0x80000000
00321|        }
00322|
00323|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00324|        {
00325|            0x80000000,
00326|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 324
Line | AML source
--------------------------------------------------------------------------------
00321|        }
00322|
00323|        Package (0x06)
00324|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00325|            0x80000000,
00326|            0x80000000,
00327|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 343
Line | AML source
--------------------------------------------------------------------------------
00340|            0x80000000
00341|        }
00342|
00343|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00344|        {
00345|            0x80000000,
00346|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 344
Line | AML source
--------------------------------------------------------------------------------
00341|        }
00342|
00343|        Package (0x06)
00344|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00345|            0x80000000,
00346|            0x80000000,
00347|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 363
Line | AML source
--------------------------------------------------------------------------------
00360|            0x80000000
00361|        }
00362|
00363|        Package (0x06)
    |              ^
    | Error 6126: syntax error, unexpected PARSEOP_PACKAGE
00364|        {
00365|            0x80000000,
00366|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 364
Line | AML source
--------------------------------------------------------------------------------
00361|        }
00362|
00363|        Package (0x06)
00364|        {
    |        ^
    | Error 6126: syntax error, unexpected '{' 
00365|            0x80000000,
00366|            0x80000000,
00367|            0x80000000,
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 383
Line | AML source
--------------------------------------------------------------------------------
00380|            0x80000000
00381|        }
00382|
00383|        Name (PSDF, Zero)
    |          ^
    | Error 6126: syntax error, unexpected PARSEOP_NAME
00384|        Method (_PSD, 0, NotSerialized)  // _PSD: Power State Dependencies
00385|        {
00386|            If (LNot (PSDF))
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 424
Line | AML source
--------------------------------------------------------------------------------
00421|            }
00422|        })
00423|    }
00424| }
    | ^                                       
    | Error 6126: syntax error, unexpected '}', expecting $end and premature End-Of-File
00425|
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] SyntaxCheckIASLCompilerAborted: Test 1, Compilation aborted early
due to a parser detected syntax error.

ADVICE: Some subsequent errors may not be detected because the compiler had to
terminate prematurely. If the compiler did not abort early then potentially
correct code may parse incorrectly producing some or many false positive errors.

Table SSDT (2) reassembly: Found 17 errors, 0 warnings, 0 remarks.


Checking ACPI table SSDT (#3)

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 150
Line | AML source
--------------------------------------------------------------------------------
00147|
00148|            Store (CPDC (Arg0), Local0)
00149|            GCAP (Local0)
00150|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00151|        }
00152|
00153|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [LOW] AMLAsmASL_MSG_SERIALIZED_REQUIRED: Test 1, Assembler remark in line
160
Line | AML source
--------------------------------------------------------------------------------
00157|            Return (Local0)
00158|        }
00159|
00160|        Method (CPDC, 1, NotSerialized)
    |                  ^
    | Remark 2120: Control Method should be made Serialized    (due to creation of named objects within)
00161|        {
00162|            CreateDWordField (Arg0, Zero, REVS)
00163|            CreateDWordField (Arg0, 0x04, SIZE)
================================================================================

ADVICE: (for Remark #2120, ASL_MSG_SERIALIZED_REQUIRED): A named object is
created inside a non-serialized method - this method should be serialized. It is
possible that one thread enters the method and blocks and then a second thread
also executes the method, ending up in two attempts to create the object and
causing a failure.

FAILED [LOW] AMLAsmUnknown: Test 1, Assembler remark in line 175
Line | AML source
--------------------------------------------------------------------------------
00172|            Return (COSC (ToUUID ("4077a616-290c-47be-9ebd-d87058713953"), REVS, SIZE, Local2))
00173|        }
00174|
00175|        Method (COSC, 4, NotSerialized)
    |                  ^
    | Remark 2146: Method Argument is never used    (Arg2)
00176|        {
00177|            CreateDWordField (Arg3, Zero, STS0)
00178|            CreateDWordField (Arg3, 0x04, CAP0)
================================================================================
FAILED [LOW] AMLAsmASL_MSG_SERIALIZED_REQUIRED: Test 1, Assembler remark in line
175
Line | AML source
--------------------------------------------------------------------------------
00172|            Return (COSC (ToUUID ("4077a616-290c-47be-9ebd-d87058713953"), REVS, SIZE, Local2))
00173|        }
00174|
00175|        Method (COSC, 4, NotSerialized)
    |                  ^
    | Remark 2120: Control Method should be made Serialized    (due to creation of named objects within)
00176|        {
00177|            CreateDWordField (Arg3, Zero, STS0)
00178|            CreateDWordField (Arg3, 0x04, CAP0)
================================================================================

ADVICE: (for Remark #2120, ASL_MSG_SERIALIZED_REQUIRED): A named object is
created inside a non-serialized method - this method should be serialized. It is
possible that one thread enters the method and blocks and then a second thread
also executes the method, ending up in two attempts to create the object and
causing a failure.

FAILED [LOW] AMLAsmASL_MSG_NOT_REFERENCED: Test 1, Assembler remark in line 178
Line | AML source
--------------------------------------------------------------------------------
00175|        Method (COSC, 4, NotSerialized)
00176|        {
00177|            CreateDWordField (Arg3, Zero, STS0)
00178|            CreateDWordField (Arg3, 0x04, CAP0)
    |                                            ^
    | Remark 2089: Object is not referenced    (Name is within method [COSC])
00179|            CreateDWordField (Arg0, Zero, IID0)
00180|            CreateDWordField (Arg0, 0x04, IID1)
00181|            CreateDWordField (Arg0, 0x08, IID2)
================================================================================
FAILED [LOW] AMLAsmASL_MSG_SERIALIZED_REQUIRED: Test 1, Assembler remark in line
204
Line | AML source
--------------------------------------------------------------------------------
00201|            Return (Arg3)
00202|        }
00203|
00204|        Method (GCAP, 1, NotSerialized)
    |                  ^
    | Remark 2120: Control Method should be made Serialized    (due to creation of named objects within)
00205|        {
00206|            CreateDWordField (Arg0, Zero, STS0)
00207|            CreateDWordField (Arg0, 0x04, CAP0)
================================================================================

ADVICE: (for Remark #2120, ASL_MSG_SERIALIZED_REQUIRED): A named object is
created inside a non-serialized method - this method should be serialized. It is
possible that one thread enters the method and blocks and then a second thread
also executes the method, ending up in two attempts to create the object and
causing a failure.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 243
Line | AML source
--------------------------------------------------------------------------------
00240|        {
00241|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00242|            GCAP (Local0)
00243|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00244|        }
00245|
00246|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [LOW] AMLAsmASL_MSG_SERIALIZED_REQUIRED: Test 1, Assembler remark in line
283
Line | AML source
--------------------------------------------------------------------------------
00280|            Return (Zero)
00281|        }
00282|
00283|        Method (APCT, 0, NotSerialized)
    |                  ^
    | Remark 2120: Control Method should be made Serialized    (due to creation of named objects within)
00284|        {
00285|            If (LAnd (And (CFGD, 0x7A), LNot (And (SDTL, 0x20))))
00286|            {
================================================================================

ADVICE: (for Remark #2120, ASL_MSG_SERIALIZED_REQUIRED): A named object is
created inside a non-serialized method - this method should be serialized. It is
possible that one thread enters the method and blocks and then a second thread
also executes the method, ending up in two attempts to create the object and
causing a failure.

FAILED [LOW] AMLAsmASL_MSG_SERIALIZED_REQUIRED: Test 1, Assembler remark in line
293
Line | AML source
--------------------------------------------------------------------------------
00290|            }
00291|        }
00292|
00293|        Method (APPT, 0, NotSerialized)
    |                  ^
    | Remark 2120: Control Method should be made Serialized    (due to creation of named objects within)
00294|        {
00295|            If (LAnd (And (CFGD, One), LNot (And (SDTL, 0x10))))
00296|            {
================================================================================

ADVICE: (for Remark #2120, ASL_MSG_SERIALIZED_REQUIRED): A named object is
created inside a non-serialized method - this method should be serialized. It is
possible that one thread enters the method and blocks and then a second thread
also executes the method, ending up in two attempts to create the object and
causing a failure.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 310
Line | AML source
--------------------------------------------------------------------------------
00307|        {
00308|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00309|            GCAP (Local0)
00310|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00311|        }
00312|
00313|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 357
Line | AML source
--------------------------------------------------------------------------------
00354|        {
00355|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00356|            GCAP (Local0)
00357|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00358|        }
00359|
00360|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 404
Line | AML source
--------------------------------------------------------------------------------
00401|        {
00402|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00403|            GCAP (Local0)
00404|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00405|        }
00406|
00407|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 451
Line | AML source
--------------------------------------------------------------------------------
00448|        {
00449|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00450|            GCAP (Local0)
00451|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00452|        }
00453|
00454|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 498
Line | AML source
--------------------------------------------------------------------------------
00495|        {
00496|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00497|            GCAP (Local0)
00498|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00499|        }
00500|
00501|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

FAILED [MEDIUM] AMLAsmASL_MSG_RESERVED_NO_RETURN_VAL: Test 1, Assembler warning
in line 545
Line | AML source
--------------------------------------------------------------------------------
00542|        {
00543|            Store (\_PR.CPU0.CPDC (Arg0), Local0)
00544|            GCAP (Local0)
00545|            Return (Local0)
    |                        ^
    | Warning 3104: Reserved method should not return a value    (_PDC)
00546|        }
00547|
00548|        Method (_OSC, 4, NotSerialized)  // _OSC: Operating System Capabilities
================================================================================

ADVICE: (for Warning #3104, ASL_MSG_RESERVED_NO_RETURN_VAL): A reserved method
returned a value however it is not expected to return anything, so this does not
conform to the expected behaviour. The kernel will most probably ignore the
return value, so this is not going to produce any run time errors.

Table SSDT (3) reassembly: Found 0 errors, 8 warnings, 7 remarks.


Checking ACPI table SSDT (#4)

FAILED [MEDIUM] AMLAsmASL_MSG_NO_REGION: Test 1, Assembler warning in line 63
Line | AML source
--------------------------------------------------------------------------------
00060|    Scope (\_SB.PCI0.SAT0)
00061|    {
00062|        Name (REGF, One)
00063|        Method (_REG, 2, NotSerialized)  // _REG: Region Availability
    |                  ^
    | Warning 3079: _REG has no corresponding Operation Region 
00064|        {
00065|            If (LEqual (Arg0, 0x02))
00066|            {
================================================================================

ADVICE: (for Warning #3079, ASL_MSG_NO_REGION): _REG requires a corresponding
Operation Region, however one was not found.

Table SSDT (4) reassembly: Found 0 errors, 1 warnings, 0 remarks.


Checking ACPI table SSDT (#5)

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4984
Line | AML source
--------------------------------------------------------------------------------
04981|                {
04982|                    If (CondRefOf (\_SB.PCI0.PEG0.PEGP.SGPO))
04983|                    {
04984|                        \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, One, \_SB.PCI0.PEG0.PEGP.SGPO (PWEN, Zero, Else
    |                                                                                                      ^
    | Error 6126: syntax error, unexpected PARSEOP_ELSE, expecting ',' or ')' 
04985|                                {
04986|                                    If (LEqual (Arg1, One))
04987|                                    {
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4992
Line | AML source
--------------------------------------------------------------------------------
04989|                                        {
04990|                                            If (CondRefOf (\_SB.PCI0.PEG0.PEGP.SGPO))
04991|                                            {
04992|                                                \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, One, \_SB.PCI0.PEG0.PEGP.SGPO (PWEN, One, Sleep (DLPW), \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, Zero, Sleep (
    |                                                                                                                              ^
    | Error 6126: syntax error, unexpected PARSEOP_SLEEP, expecting ',' or ')' 
04993|                                                    DLHR))))
04994|                                            }
04995|                                        }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4992
Line | AML source
--------------------------------------------------------------------------------
04989|                                        {
04990|                                            If (CondRefOf (\_SB.PCI0.PEG0.PEGP.SGPO))
04991|                                            {
04992|                                                \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, One, \_SB.PCI0.PEG0.PEGP.SGPO (PWEN, One, Sleep (DLPW), \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, Zero, Sleep (
    |                                                                                                                                      ^
    | Error 6126: syntax error, unexpected ',' 
04993|                                                    DLHR))))
04994|                                            }
04995|                                        }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4992
Line | AML source
--------------------------------------------------------------------------------
04989|                                        {
04990|                                            If (CondRefOf (\_SB.PCI0.PEG0.PEGP.SGPO))
04991|                                            {
04992|                                                \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, One, \_SB.PCI0.PEG0.PEGP.SGPO (PWEN, One, Sleep (DLPW), \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, Zero, Sleep (
    |                                                                                                                                                                                  ^
    | Error 6126: syntax error, unexpected PARSEOP_SLEEP, expecting ',' or ')' 
04993|                                                    DLHR))))
04994|                                            }
04995|                                        }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4993
Line | AML source
--------------------------------------------------------------------------------
04990|                                            If (CondRefOf (\_SB.PCI0.PEG0.PEGP.SGPO))
04991|                                            {
04992|                                                \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, One, \_SB.PCI0.PEG0.PEGP.SGPO (PWEN, One, Sleep (DLPW), \_SB.PCI0.PEG0.PEGP.SGPO (HLRS, Zero, Sleep (
04993|                                                    DLHR))))
    |                                                        ^
    | Error 6126: syntax error, unexpected ')' 
04994|                                            }
04995|                                        }
04996|                                    }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 4997
Line | AML source
--------------------------------------------------------------------------------
04994|                                            }
04995|                                        }
04996|                                    }
04997|                                }))
    |                                ^
    | Error 6126: syntax error, unexpected ')' 
04998|                    }
04999|                }
05000|            }
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] AMLAsmASL_MSG_SYNTAX: Test 1, Assembler error in line 5050
Line | AML source
--------------------------------------------------------------------------------
05047|            }
05048|        }
05049|    }
05050| }
    | ^                                       
    | Error 6126: syntax error, unexpected '}', expecting $end and premature End-Of-File
05051|
================================================================================

ADVICE: (for Error #6126, ASL_MSG_SYNTAX): The disassembled code cannot be
reassembled using the strict IASL compiler as it contains syntax errors.

FAILED [HIGH] SyntaxCheckIASLCompilerAborted: Test 1, Compilation aborted early
due to a parser detected syntax error.

ADVICE: Some subsequent errors may not be detected because the compiler had to
terminate prematurely. If the compiler did not abort early then potentially
correct code may parse incorrectly producing some or many false positive errors.

Table SSDT (5) reassembly: Found 7 errors, 0 warnings, 0 remarks.


================================================================================
1 passed, 48 failed, 0 warning, 0 aborted, 0 skipped, 0 info only.
================================================================================

Code:


dmicheck: DMI/SMBIOS table tests.
--------------------------------------------------------------------------------
Test 1 of 2: Find and test SMBIOS Table Entry Points.
This test tries to find and sanity check the SMBIOS data structures.
PASSED: Test 1, Found SMBIOS Table Entry Point at 0xf04c0
SMBIOS Entry Point Structure:
  Anchor String          : _SM_
  Checksum              : 0x64
  Entry Point Length    : 0x1f
  Major Version          : 0x02
  Minor Version          : 0x08
  Maximum Struct Size    : 0x114
  Entry Point Revision  : 0x00
  Formatted Area        : 0x00 0x00 0x00 0x00 0x00
  Intermediate Anchor    : _DMI_
  Intermediate Checksum  : 0x4d
  Structure Table Length : 0x0aec
  Structure Table Address: 0x000edae0
  # of SMBIOS Structures : 0x0036
  SBMIOS BCD Revision    : 27

PASSED: Test 1, SMBIOS Table Entry Point Checksum is valid.
PASSED: Test 1, SMBIOS Table Entry Point Length is valid.
PASSED: Test 1, SMBIOS Table Entry Intermediate Anchor String _DMI_ is valid.
PASSED: Test 1, SMBIOS Table Entry Point Intermediate Checksum is valid.
PASSED: Test 1, SMBIOS Table Entry Structure Table Address and Length looks
valid.

Test 2 of 2: Test DMI/SMBIOS tables for errors.
PASSED: Test 2, Entry @ 0x000edae0 'BIOS Information (Type 0)'
PASSED: Test 2, Entry @ 0x000edb0e 'System Information (Type 1)'
PASSED: Test 2, Entry @ 0x000edb70 'Base Board Information (Type 2)'
PASSED: Test 2, Entry @ 0x000edba1 'Chassis Information (Type 3)'
PASSED: Test 2, Entry @ 0x000edbda 'System Slot Information (Type 9)'
PASSED: Test 2, Entry @ 0x000edc01 'System Slot Information (Type 9)'
PASSED: Test 2, Entry @ 0x000edc2a 'OEM Strings (Type 11)'
PASSED: Test 2, Entry @ 0x000edcc4 'System Configuration Options (Type 12)'
PASSED: Test 2, Entry @ 0x000edce1 'Hardware Security (Type 24)'
PASSED: Test 2, Entry @ 0x000edce8 'System Boot Information (Type 32)'
PASSED: Test 2, Entry @ 0x000edcfe 'Management Device (Type 34)'
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x0b) while accessing entry 'Voltage Probe (Type 26)' @ 0x000edd11, field
'Location (bits 0..4)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.

FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x06) while accessing entry 'Voltage Probe (Type 26)' @ 0x000edd11, field
'Status (bits 5..7)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.


ADVICE: It may be worth checking against section 7.27 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000edd2e 'Management Device Threshold Data (Type 36)'
PASSED: Test 2, Entry @ 0x000edd40 'Management Device Component (Type 35)'
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x0f) while accessing entry 'Temperature Probe (Type 28)' @ 0x000edd4e,
field 'Location (bits 0..4)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.

FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x06) while accessing entry 'Temperature Probe (Type 28)' @ 0x000edd4e,
field 'Status (bits 5..7)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.


ADVICE: It may be worth checking against section 7.29 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000edd6b 'Management Device Threshold Data (Type 36)'
PASSED: Test 2, Entry @ 0x000edd7d 'Management Device Component (Type 35)'
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x12 (range allowed
0x01..0x09, 0x10..0x11) while accessing entry 'Cooling Device (Type 27)' @
0x000edd8b, field 'Device Type', offset 0x06, mask 0x1f
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x06) while accessing entry 'Cooling Device (Type 27)' @ 0x000edd8b, field
'Status (bits 5..7)', offset 0x06

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.


ADVICE: It may be worth checking against section 7.28 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000edda9 'Management Device Threshold Data (Type 36)'
PASSED: Test 2, Entry @ 0x000eddbb 'Management Device Component (Type 35)'
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x12 (range allowed
0x01..0x09, 0x10..0x11) while accessing entry 'Cooling Device (Type 27)' @
0x000eddc9, field 'Device Type', offset 0x06, mask 0x1f
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x06) while accessing entry 'Cooling Device (Type 27)' @ 0x000eddc9, field
'Status (bits 5..7)', offset 0x06

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.


ADVICE: It may be worth checking against section 7.28 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000eddda 'Management Device Threshold Data (Type 36)'
PASSED: Test 2, Entry @ 0x000eddec 'Management Device Component (Type 35)'
FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x0b) while accessing entry 'Electrical Current Probe (Type 29)' @
0x000eddfa, field 'Location (bits 0..4)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.

FAILED [HIGH] DMIValueOutOfRange: Test 2, Out of range value 0x00 (range allowed
0x01..0x06) while accessing entry 'Electrical Current Probe (Type 29)' @
0x000eddfa, field 'Status (bits 5..7)', offset 0x05

ADVICE: A value that is out of range is incorrect and not conforming to the
SMBIOS specification. This field is not currently used by the Linux kernel, so
this firmware bug shouldn't cause any problems.


ADVICE: It may be worth checking against section 7.30 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000ede15 'Management Device Threshold Data (Type 36)'
PASSED: Test 2, Entry @ 0x000ede27 'Management Device Component (Type 35)'
PASSED: Test 2, Entry @ 0x000ede35 'Voltage Probe (Type 26)'
PASSED: Test 2, Entry @ 0x000ede52 'Temperature Probe (Type 28)'
PASSED: Test 2, Entry @ 0x000ede6f 'Cooling Device (Type 27)'
PASSED: Test 2, Entry @ 0x000ede8d 'Electrical Current Probe (Type 29)'
PASSED: Test 2, Entry @ 0x000edea8 'System Power Supply (Type 39)'
PASSED: Test 2, Entry @ 0x000edf60 'Onboard Device (Type 41)'
PASSED: Test 2, Entry @ 0x000edf79 'Onboard Device (Type 41)'
FAILED [MEDIUM] DMIReservedValueUsed: Test 2, Reserved bits 0x00ec was usedbits
8..15 would be reserved while accessing entry 'Processor Information (Type 4)' @
0x000edf92, field 'Processor Characteristics', offset 0x26

ADVICE: It may be worth checking against section 7.5 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000edff1 'Cache Information (Type 7)'
PASSED: Test 2, Entry @ 0x000ee015 'Cache Information (Type 7)'
PASSED: Test 2, Entry @ 0x000ee039 'Cache Information (Type 7)'
PASSED: Test 2, Entry @ 0x000ee05d 'Physical Memory Array (Type 16)'
FAILED [LOW] DMISerialNumber: Test 2, String index 0x03 in table entry 'Memory
Device (Type 17)' @ 0x000ee076, field 'Manufacturer', offset 0x17 has a default
value '[Empty]' and probably has not been updated by the BIOS vendor.

ADVICE: The DMI table contains data which is clearly been left in a default
setting and not been configured for this machine. Somebody has probably
forgotten to define this field and it basically means this field is effectively
useless, however the kernel does not use this data so the issue is fairly low.

FAILED [LOW] DMISerialNumber: Test 2, String index 0x04 in table entry 'Memory
Device (Type 17)' @ 0x000ee076, field 'Serial Number', offset 0x18 has a default
value '[Empty]' and probably has not been updated by the BIOS vendor.

ADVICE: The DMI table contains data which is clearly been left in a default
setting and not been configured for this machine. Somebody has probably
forgotten to define this field and it basically means this field is effectively
useless, however the kernel does not use this data so the issue is fairly low.

FAILED [LOW] DMISerialNumber: Test 2, String index 0x06 in table entry 'Memory
Device (Type 17)' @ 0x000ee076, field 'Part Number', offset 0x1a has a default
value '[Empty]' and probably has not been updated by the BIOS vendor.

ADVICE: The DMI table contains data which is clearly been left in a default
setting and not been configured for this machine. Somebody has probably
forgotten to define this field and it basically means this field is effectively
useless, however the kernel does not use this data so the issue is fairly low.


ADVICE: It may be worth checking against section 7.18 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

FAILED [LOW] DMIAssetTag: Test 2, String index 0x05 in table entry 'Memory
Device (Type 17)' @ 0x000ee0cf, field 'Asset Tag', offset 0x19 has a default
value '9876543210' and probably has not been updated by the BIOS vendor.

ADVICE: The DMI table contains data which is clearly been left in a default
setting and not been configured for this machine. Somebody has probably
forgotten to define this field and it basically means this field is effectively
useless, however the kernel does not use this data so the issue is fairly low.


ADVICE: It may be worth checking against section 7.18 of the System Management
BIOS (SMBIOS) Reference Specification (see hxxp://www.dmtf.org/standards
/smbios).

PASSED: Test 2, Entry @ 0x000ee13a 'Memory Array Mapped Address (Type 19)'
PASSED: Test 2, Entry @ 0x000ee15b 'Memory Device Mapped Address (Type 20)'
PASSED: Test 2, Entry @ 0x000ee180 'Unknown (Type 208)'
PASSED: Test 2, Entry @ 0x000ee187 'BIOS Language Information (Type 13)'
PASSED: Test 2, Entry @ 0x000ee26a 'Unknown (Type 136)'
PASSED: Test 2, Entry @ 0x000ee272 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee295 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee2e3 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee3f7 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee456 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee526 'Unknown (Type 221)'
PASSED: Test 2, Entry @ 0x000ee556 'Group Associations (Type 14)'
PASSED: Test 2, Entry @ 0x000ee584 'Unknown (Type 131)'
PASSED: Test 2, Entry @ 0x000ee5c6 'End of Table (Type 127)'
SKIPPED: Test 2, Cannot find SMBIOS30 table entry, skip the test.

================================================================================
52 passed, 15 failed, 0 warning, 0 aborted, 1 skipped, 0 info only.
================================================================================


Code:

aspm: PCIe ASPM test.
--------------------------------------------------------------------------------
Test 1 of 2: PCIe ASPM ACPI test.
PCIe ASPM is not controlled by Linux kernel.

ADVICE: BIOS reports that Linux kernel should not modify ASPM settings that BIOS
configured. It can be intentional because hardware vendors identified some
capability bugs between the motherboard and the add-on cards.


Test 2 of 2: PCIe ASPM registers test.
WARNING: Test 2, RP 00h:1Ch.03h L0s not enabled.
WARNING: Test 2, Device 03h:00h.00h L0s not enabled.

ADVICE: The ASPM L0s low power Link state is optimized for short entry and exit
latencies, while providing substantial power savings. Disabling L0s of a PCIe
device may increases power consumption, and will impact the battery life of a
mobile system.

PASSED: Test 2, PCIe ASPM setting matched was matched.

Code:

oops: Scan kernel log for Oopses.
--------------------------------------------------------------------------------
Test 1 of 1: Kernel log oops check.
PASSED: Test 1, Found no oopses in kernel log.
PASSED: Test 1, Found no WARN_ON warnings in kernel log.

================================================================================
2 passed, 0 failed, 0 warning, 0 aborted, 0 skipped, 0 info only.
================================================================================

klog: Scan kernel log for errors and warnings.
--------------------------------------------------------------------------------
Test 1 of 1: Kernel log error check.
Kernel message: [ 0.016926] ENERGY_PERF_BIAS: Set to 'normal', was 'performance'

ADVICE: This is not exactly a failure but a warning from the kernel. The
MSR_IA32_ENERGY_PERF_BIAS was initialized and defaulted to a high performance
bias setting. The kernel has detected this and changed it down to a 'normal'
bias setting.

Kernel message: [ 0.111628] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep
State [\_S1_] (20150619/hwxface-580)

ADVICE: The exception comes from kernel cannot find _S1 namespace object that
contains the register values for the sleep state when kernel would like to setup
all the sleep state information. This means that the kernel does not know how to
enter the S1 sleep state, however, it should not be a problem if the S1 sleep
state isn't supported intentionally.

Kernel message: [ 0.111634] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep
State [\_S2_] (20150619/hwxface-580)

ADVICE: The exception comes from kernel cannot find _S2 namespace object that
contains the register values for the sleep state when kernel would like to setup
all the sleep state information. This means that the kernel does not know how to
enter the S2 sleep state, however, it should not be a problem if the S2 sleep
state isn't supported intentionally.

FAILED [HIGH] KlogAcpiFieldExceedsBuffer: Test 1, HIGH Kernel message: [
81.084363] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160
(bits) (20150619/dsopcode-236)
Message repeated 9 times.

ADVICE: Failed to initialise an ACPI buffer field, the field exceeded the buffer
size provided. This is a firmware bug.

FAILED [HIGH] KlogAcpiBufferLimit: Test 1, HIGH Kernel message: [ 81.084367]
ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0),
AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Message repeated 9 times.

ADVICE: Generally this error occurs because of access outside of a buffer. This
occurs for several reasons: a) A field does not fit within the current length of
a buffer, b) an ACPI table load did not fit into a buffer, c) An attempt to
convert a buffer into an integer failed because the buffer was zero sized, d) a
SMBus/IPMI/GenericSerialBus write failed because the buffer was too small, e) An
index into a buffer was too long and fell outside the buffer.

FAILED [HIGH] KlogAcpiBufferLimit: Test 1, HIGH Kernel message: [ 81.084380]
ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node
ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
Message repeated 9 times.

ADVICE: Generally this error occurs because of access outside of a buffer. This
occurs for several reasons: a) A field does not fit within the current length of
a buffer, b) an ACPI table load did not fit into a buffer, c) An attempt to
convert a buffer into an integer failed because the buffer was zero sized, d) a
SMBus/IPMI/GenericSerialBus write failed because the buffer was too small, e) An
index into a buffer was too long and fell outside the buffer.

Found 3 unique errors in kernel log.

================================================================================
0 passed, 3 failed, 0 warning, 0 aborted, 0 skipped, 0 info only.
===================================================================


Code:


Test Failure Summary
================================================================================

Critical failures: NONE

High failures: 41
 klog: HIGH Kernel message: [  81.084363] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
 klog: HIGH Kernel message: [  81.084367] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
 klog: HIGH Kernel message: [  81.084380] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x0b) while accessing entry 'Voltage Probe (Type 26)' @ 0x000edd11, field 'Location (bits 0..4)', offset 0x05
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x06) while accessing entry 'Voltage Probe (Type 26)' @ 0x000edd11, field 'Status (bits 5..7)', offset 0x05
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x0f) while accessing entry 'Temperature Probe (Type 28)' @ 0x000edd4e, field 'Location (bits 0..4)', offset 0x05
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x06) while accessing entry 'Temperature Probe (Type 28)' @ 0x000edd4e, field 'Status (bits 5..7)', offset 0x05
 dmicheck: Out of range value 0x12 (range allowed 0x01..0x09, 0x10..0x11) while accessing entry 'Cooling Device (Type 27)' @ 0x000edd8b, field 'Device Type', offset 0x06, mask 0x1f
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x06) while accessing entry 'Cooling Device (Type 27)' @ 0x000edd8b, field 'Status (bits 5..7)', offset 0x06
 dmicheck: Out of range value 0x12 (range allowed 0x01..0x09, 0x10..0x11) while accessing entry 'Cooling Device (Type 27)' @ 0x000eddc9, field 'Device Type', offset 0x06, mask 0x1f
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x06) while accessing entry 'Cooling Device (Type 27)' @ 0x000eddc9, field 'Status (bits 5..7)', offset 0x06
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x0b) while accessing entry 'Electrical Current Probe (Type 29)' @ 0x000eddfa, field 'Location (bits 0..4)', offset 0x05
 dmicheck: Out of range value 0x00 (range allowed 0x01..0x06) while accessing entry 'Electrical Current Probe (Type 29)' @ 0x000eddfa, field 'Status (bits 5..7)', offset 0x05
 syntaxcheck: Assembler error in line 6740
 syntaxcheck: Assembler error in line 10817
 syntaxcheck: Assembler error in line 20852
 syntaxcheck: Assembler error in line 21193
 syntaxcheck: Assembler error in line 25106
 syntaxcheck: Compilation aborted early due to a parser detected syntax error.
 syntaxcheck: Assembler error in line 223
 syntaxcheck: Assembler error in line 243
 syntaxcheck: Assembler error in line 244
 syntaxcheck: Assembler error in line 263
 syntaxcheck: Assembler error in line 264
 syntaxcheck: Assembler error in line 283
 syntaxcheck: Assembler error in line 284
 syntaxcheck: Assembler error in line 303
 syntaxcheck: Assembler error in line 304
 syntaxcheck: Assembler error in line 323
 syntaxcheck: Assembler error in line 324
 syntaxcheck: Assembler error in line 343
 syntaxcheck: Assembler error in line 344
 syntaxcheck: Assembler error in line 363
 syntaxcheck: Assembler error in line 364
 syntaxcheck: Assembler error in line 383
 syntaxcheck: Assembler error in line 424
 syntaxcheck: Assembler error in line 4984
 syntaxcheck: Assembler error in line 4992
 syntaxcheck: Assembler error in line 4993
 syntaxcheck: Assembler error in line 4997
 syntaxcheck: Assembler error in line 5050

Medium failures: 32
 dmicheck: Reserved bits 0x00ec was usedbits 8..15 would be reserved while accessing entry 'Processor Information (Type 4)' @ 0x000edf92, field 'Processor Characteristics', offset 0x26
 msr: MSR 0x000004c8 A_PMC7 has 1 inconsistent values across 2 CPUs (shift: 0 mask: 0xffffffffffffffff).
 cpufreq: CPU max frequency is unreachable
 cpufreq: Can't set CPU frequencies
 virt: Virtualization extensions supported but disabled by BIOS.
 apicedge: Non-Legacy interrupt 0 is incorrectly level triggered.
 apicedge: Non-Legacy interrupt 1 is incorrectly level triggered.
 apicedge: Non-Legacy interrupt 8 is incorrectly level triggered.
 apicedge: Non-Legacy interrupt 12 is incorrectly level triggered.
 wmi: GUID 2B814318-4BE8-4707-9D84-A190A859B5D0 is unknown to the kernel, a driver may need to be implemented for this GUID.
 syntaxcheck: Assembler warning in line 150
 syntaxcheck: Assembler warning in line 243
 syntaxcheck: Assembler warning in line 310
 syntaxcheck: Assembler warning in line 357
 syntaxcheck: Assembler warning in line 404
 syntaxcheck: Assembler warning in line 451
 syntaxcheck: Assembler warning in line 498
 syntaxcheck: Assembler warning in line 545
 syntaxcheck: Assembler warning in line 63
 method: \NFC_._HID returned a integer 0x00000000 (EISA ID @@@0000) but the this is not a valid EISA ID encoded PNP ID.
 method: \_SB_.PCI0.RP01.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP02.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP03.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP04.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP05.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP06.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP07.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.RP08.PXSX.WRST._STA returned a NULL object, and did not return ACPI_TYPE_INTEGER.
 method: \_SB_.PCI0.SAT0.NVM0._PS0 returned values, but was expected to return nothing.
 method: \_SB_.PCI0.SAT0.NVM0._PS3 returned values, but was expected to return nothing.
 method: \_PR_.CPU0._PCT returned a NULL object, and did not return ACPI_TYPE_PACKAGE.
 fan: Fan present but has no cur_state present.

Low failures: 10
 dmicheck: String index 0x03 in table entry 'Memory Device (Type 17)' @ 0x000ee076, field 'Manufacturer', offset 0x17 has a default value '[Empty]' and probably has not been updated by the BIOS vendor.
 dmicheck: String index 0x04 in table entry 'Memory Device (Type 17)' @ 0x000ee076, field 'Serial Number', offset 0x18 has a default value '[Empty]' and probably has not been updated by the BIOS vendor.
 dmicheck: String index 0x06 in table entry 'Memory Device (Type 17)' @ 0x000ee076, field 'Part Number', offset 0x1a has a default value '[Empty]' and probably has not been updated by the BIOS vendor.
 dmicheck: String index 0x05 in table entry 'Memory Device (Type 17)' @ 0x000ee0cf, field 'Asset Tag', offset 0x19 has a default value '9876543210' and probably has not been updated by the BIOS vendor.
 syntaxcheck: Assembler remark in line 160
 syntaxcheck: Assembler remark in line 175
 syntaxcheck: Assembler remark in line 178
 syntaxcheck: Assembler remark in line 204
 syntaxcheck: Assembler remark in line 283
 syntaxcheck: Assembler remark in line 293

Other failures: NONE

Test          |Pass |Fail |Abort|Warn |Skip |Info |
---------------+-----+-----+-----+-----+-----+-----+
acpiinfo      |    |    |    |    |    |    3|
acpitables    |  18|    |    |    |    |    |
apicedge      |    |    4|    |    |    |    |
apicinstance  |    1|    |    |    |    |    |
asf            |    |    |    |    |    1|    |
aspm          |    1|    |    |    2|    |    |
autobrightness |    |    |    |    |    |    |
bert          |    |    |    |    |    1|    |
bgrt          |    |    |    |    |    1|    |
bios32        |    |    |    |    |    |    |
bios_info      |    |    |    |    |    |    1|
boot          |    |    |    |    |    1|    |
checksum      |  20|    |    |    |    |    |
cpep          |    |    |    |    |    1|    |
cpufreq        |    3|    2|    |    2|    2|    |
crs            |    |    |    |    |    1|    |
csm            |    |    |    |    |    |    1|
csrt          |    |    |    |    |    1|    |
cstates        |    3|    |    |    |    |    |
dbg2          |    |    |    |    |    1|    |
dbgp          |    1|    |    |    |    |    |
dmar          |    |    |    |    |    1|    |
dmicheck      |  52|  15|    |    |    1|    |
ebda          |    1|    |    |    |    |    |
ecdt          |    |    |    |    |    1|    |
erst          |    |    |    |    |    1|    |
facs          |    1|    |    |    |    |    |
fadt          |    4|    |    |    |    |    |
fan            |    7|    1|    |    |    |    |
fpdt          |    1|    |    |    |    |    |
gtdt          |    |    |    |    |    1|    |
hda_audio      |    |    |    |    |    1|    |
hest          |    |    |    |    |    1|    |
hpet          |    5|    |    |    |    |    |
iort          |    |    |    |    |    1|    |
klog          |    |    3|    |    |    |    |
lpit          |    |    |    |    |    1|    |
madt          |    1|    |    |    |    |    |
maxfreq        |    1|    |    |    |    |    |
maxreadreq    |    1|    |    |    |    |    |
mcfg          |    2|    |    |    |    |    |
mchi          |    |    |    |    |    1|    |
method        |  553|  12|    |    |  132|    |
microcode      |    |    |    |    |    1|    |
mpcheck        |    9|    |    |    |    |    |
msdm          |    |    |    |    |    1|    |
msr            |  114|    1|    |    |    |    |
mtrr          |    2|    |    |    |    1|    |
nx            |    3|    |    |    |    |    |
oops          |    2|    |    |    |    |    |
osilinux      |    1|    |    |    |    |    |
pcc            |    |    |    |    |    |    1|
pciirq        |    4|    |    |    |    |    |
pnp            |    2|    |    |    |    |    |
rsdp          |    1|    |    |    |    |    |
rsdt          |    1|    |    |    |    |    |
sbst          |    |    |    |    |    1|    |
securebootcert |    |    |    |    |    1|    |
slic          |    |    |    |    |    1|    |
slit          |    |    |    |    |    1|    |
spcr          |    |    |    |    |    1|    |
spmi          |    |    |    |    |    1|    |
srat          |    |    |    |    |    1|    |
stao          |    |    |    |    |    1|    |
syntaxcheck    |    1|  48|    |    |    |    |
tcpa          |    1|    |    |    |    |    |
tpm2          |    |    |    1|    |    |    |
uefi          |    1|    |    |    |    |    |
uefibootpath  |    |    |    1|    |    |    |
version        |    |    |    |    |    |    4|
virt          |    |    1|    |    |    |    |
waet          |    |    |    |    |    1|    |
wakealarm      |    4|    |    |    |    |    |
wdat          |    |    |    |    |    1|    |
wmi            |    3|    1|    |    |    |    |
xenv          |    |    |    1|    |    |    |
xsdt          |    1|    |    |    |    |    |
---------------+-----+-----+-----+-----+-----+-----+
Total:        |  826|  88|    3|    4|  165|  10|
---------------+-----+-----+-----+-----+-----+-----+


dennissteins 15.03.2016 11:26

dmesg DUMP

Code:

<6>[    0.000000] Initializing cgroup subsys cpuset
<6>[    0.000000] Initializing cgroup subsys cpu
<6>[    0.000000] Initializing cgroup subsys cpuacct
<5>[    0.000000] Linux version 4.2.0-16-generic (buildd@lcy01-07) (gcc version 5.2.1 20151003 (Ubuntu 5.2.1-21ubuntu2) ) #19-Ubuntu SMP Thu Oct 8 15:35:06 UTC 2015 (Ubuntu 4.2.0-16.19-generic 4.2.3)
<6>[    0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.2.0-16-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
<6>[    0.000000] KERNEL supported cpus:
<6>[    0.000000]  Intel GenuineIntel
<6>[    0.000000]  AMD AuthenticAMD
<6>[    0.000000]  Centaur CentaurHauls
<6>[    0.000000] x86/fpu: Supporting XSAVE feature 0x01: 'x87 floating point registers'
<6>[    0.000000] x86/fpu: Supporting XSAVE feature 0x02: 'SSE registers'
<6>[    0.000000] x86/fpu: Enabled xstate features 0x3, context size is 0x240 bytes, using 'standard' format.
<6>[    0.000000] x86/fpu: Using 'eager' FPU context switches.
<6>[    0.000000] e820: BIOS-provided physical RAM map:
<6>[    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009d7ff] usable
<6>[    0.000000] BIOS-e820: [mem 0x000000000009d800-0x000000000009ffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000c8b3bfff] usable
<6>[    0.000000] BIOS-e820: [mem 0x00000000c8b3c000-0x00000000c8b42fff] ACPI NVS
<6>[    0.000000] BIOS-e820: [mem 0x00000000c8b43000-0x00000000c9601fff] usable
<6>[    0.000000] BIOS-e820: [mem 0x00000000c9602000-0x00000000c98c2fff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000c98c3000-0x00000000dbaf6fff] usable
<6>[    0.000000] BIOS-e820: [mem 0x00000000dbaf7000-0x00000000dbb5ffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000dbb60000-0x00000000dbb89fff] ACPI data
<6>[    0.000000] BIOS-e820: [mem 0x00000000dbb8a000-0x00000000dbceffff] ACPI NVS
<6>[    0.000000] BIOS-e820: [mem 0x00000000dbcf0000-0x00000000dbffefff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000dbfff000-0x00000000dbffffff] usable
<6>[    0.000000] BIOS-e820: [mem 0x00000000dd000000-0x00000000df1fffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000f8000000-0x00000000fbffffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000fed00000-0x00000000fed03fff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000fed1c000-0x00000000fed1ffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x00000000ff000000-0x00000000ffffffff] reserved
<6>[    0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fdfffff] usable
<6>[    0.000000] NX (Execute Disable) protection: active
<6>[    0.000000] SMBIOS 2.8 present.
<7>[    0.000000] DMI: Hewlett-Packard HP 280 G1 MT/2B34, BIOS 80.14 09/28/2015
<7>[    0.000000] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
<7>[    0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
<6>[    0.000000] e820: last_pfn = 0x11fe00 max_arch_pfn = 0x400000000
<7>[    0.000000] MTRR default type: uncachable
<7>[    0.000000] MTRR fixed ranges enabled:
<7>[    0.000000]  00000-9FFFF write-back
<7>[    0.000000]  A0000-BFFFF uncachable
<7>[    0.000000]  C0000-CFFFF write-protect
<7>[    0.000000]  D0000-E7FFF uncachable
<7>[    0.000000]  E8000-FFFFF write-protect
<7>[    0.000000] MTRR variable ranges enabled:
<7>[    0.000000]  0 base 0000000000 mask 7F00000000 write-back
<7>[    0.000000]  1 base 0100000000 mask 7FE0000000 write-back
<7>[    0.000000]  2 base 00E0000000 mask 7FE0000000 uncachable
<7>[    0.000000]  3 base 00DE000000 mask 7FFE000000 uncachable
<7>[    0.000000]  4 base 00DD000000 mask 7FFF000000 uncachable
<7>[    0.000000]  5 base 011FE00000 mask 7FFFE00000 uncachable
<7>[    0.000000]  6 disabled
<7>[    0.000000]  7 disabled
<7>[    0.000000]  8 disabled
<7>[    0.000000]  9 disabled
<6>[    0.000000] x86/PAT: Configuration [0-7]: WB  WC  UC- UC  WB  WC  UC- WT 
<7>[    0.000000] original variable MTRRs
<7>[    0.000000] reg 0, base: 0GB, range: 4GB, type WB
<7>[    0.000000] reg 1, base: 4GB, range: 512MB, type WB
<7>[    0.000000] reg 2, base: 3584MB, range: 512MB, type UC
<7>[    0.000000] reg 3, base: 3552MB, range: 32MB, type UC
<7>[    0.000000] reg 4, base: 3536MB, range: 16MB, type UC
<7>[    0.000000] reg 5, base: 4606MB, range: 2MB, type UC
<6>[    0.000000] total RAM covered: 4046M
<6>[    0.000000] Found optimal setting for mtrr clean up
<6>[    0.000000]  gran_size: 64K        chunk_size: 64M        num_reg: 7          lose cover RAM: 0G
<7>[    0.000000] New variable MTRRs
<7>[    0.000000] reg 0, base: 0GB, range: 2GB, type WB
<7>[    0.000000] reg 1, base: 2GB, range: 1GB, type WB
<7>[    0.000000] reg 2, base: 3GB, range: 512MB, type WB
<7>[    0.000000] reg 3, base: 3536MB, range: 16MB, type UC
<7>[    0.000000] reg 4, base: 3552MB, range: 32MB, type UC
<7>[    0.000000] reg 5, base: 4GB, range: 512MB, type WB
<7>[    0.000000] reg 6, base: 4606MB, range: 2MB, type UC
<7>[    0.000000] e820: update [mem 0xdd000000-0xffffffff] usable ==> reserved
<6>[    0.000000] e820: last_pfn = 0xdc000 max_arch_pfn = 0x400000000
<6>[    0.000000] found SMP MP-table at [mem 0x000fd7c0-0x000fd7cf] mapped at [ffff8800000fd7c0]
<6>[    0.000000] Scanning 1 areas for low memory corruption
<7>[    0.000000] Base memory trampoline at [ffff880000097000] 97000 size 24576
<6>[    0.000000] Using GB pages for direct mapping
<6>[    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
<7>[    0.000000]  [mem 0x00000000-0x000fffff] page 4k
<7>[    0.000000] BRK [0x01ff0000, 0x01ff0fff] PGTABLE
<7>[    0.000000] BRK [0x01ff1000, 0x01ff1fff] PGTABLE
<7>[    0.000000] BRK [0x01ff2000, 0x01ff2fff] PGTABLE
<6>[    0.000000] init_memory_mapping: [mem 0x11fc00000-0x11fdfffff]
<7>[    0.000000]  [mem 0x11fc00000-0x11fdfffff] page 2M
<7>[    0.000000] BRK [0x01ff3000, 0x01ff3fff] PGTABLE
<6>[    0.000000] init_memory_mapping: [mem 0x100000000-0x11fbfffff]
<7>[    0.000000]  [mem 0x100000000-0x11fbfffff] page 2M
<6>[    0.000000] init_memory_mapping: [mem 0xc0000000-0xc8b3bfff]
<7>[    0.000000]  [mem 0xc0000000-0xc89fffff] page 2M
<7>[    0.000000]  [mem 0xc8a00000-0xc8b3bfff] page 4k
<7>[    0.000000] BRK [0x01ff4000, 0x01ff4fff] PGTABLE
<7>[    0.000000] BRK [0x01ff5000, 0x01ff5fff] PGTABLE
<6>[    0.000000] init_memory_mapping: [mem 0xc8b43000-0xc9601fff]
<7>[    0.000000]  [mem 0xc8b43000-0xc8bfffff] page 4k
<7>[    0.000000]  [mem 0xc8c00000-0xc95fffff] page 2M
<7>[    0.000000]  [mem 0xc9600000-0xc9601fff] page 4k
<6>[    0.000000] init_memory_mapping: [mem 0xc98c3000-0xdbaf6fff]
<7>[    0.000000]  [mem 0xc98c3000-0xc99fffff] page 4k
<7>[    0.000000]  [mem 0xc9a00000-0xdb9fffff] page 2M
<7>[    0.000000]  [mem 0xdba00000-0xdbaf6fff] page 4k
<6>[    0.000000] init_memory_mapping: [mem 0xdbfff000-0xdbffffff]
<7>[    0.000000]  [mem 0xdbfff000-0xdbffffff] page 4k
<6>[    0.000000] init_memory_mapping: [mem 0x00100000-0xbfffffff]
<7>[    0.000000]  [mem 0x00100000-0x001fffff] page 4k
<7>[    0.000000]  [mem 0x00200000-0x3fffffff] page 2M
<7>[    0.000000]  [mem 0x40000000-0xbfffffff] page 1G
<6>[    0.000000] RAMDISK: [mem 0x33ba0000-0x35dc7fff]
<6>[    0.000000] ACPI: Early table checksum verification disabled
<4>[    0.000000] ACPI: RSDP 0x00000000000F0490 000024 (v02 HPQOEM)
<4>[    0.000000] ACPI: XSDT 0x00000000DBB69088 000094 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<4>[    0.000000] ACPI: FACP 0x00000000DBB81FA0 00010C (v05 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<4>[    0.000000] ACPI: DSDT 0x00000000DBB691B0 018DEC (v02 HPQOEM SLIC-CPC 00008014 INTL 20120711)
<4>[    0.000000] ACPI: FACS 0x00000000DBCEFF80 000040
<4>[    0.000000] ACPI: APIC 0x00000000DBB820B0 000062 (v03 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<4>[    0.000000] ACPI: FPDT 0x00000000DBB82118 000044 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<4>[    0.000000] ACPI: FIDT 0x00000000DBB82160 00009C (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<4>[    0.000000] ACPI: TCPA 0x00000000DBB82200 000032 (v02 HPQOEM SLIC-CPC 00000001 MSFT 01000013)
<4>[    0.000000] ACPI: SSDT 0x00000000DBB82238 000C7D (v02 HPQOEM SLIC-CPC 00001000 INTL 20120711)
<4>[    0.000000] ACPI: SSDT 0x00000000DBB82EB8 000539 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
<4>[    0.000000] ACPI: SSDT 0x00000000DBB833F8 000B74 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
<4>[    0.000000] ACPI: MCFG 0x00000000DBB83F70 00003C (v01 HPQOEM SLIC-CPC 01072009 MSFT 00000097)
<4>[    0.000000] ACPI: HPET 0x00000000DBB83FB0 000038 (v01 HPQOEM SLIC-CPC 01072009 AMI. 00000005)
<4>[    0.000000] ACPI: SSDT 0x00000000DBB83FE8 00036D (v01 HPQOEM SLIC-CPC 00001000 INTL 20120711)
<4>[    0.000000] ACPI: SSDT 0x00000000DBB84358 005722 (v02 HPQOEM SLIC-CPC 00003000 INTL 20120711)
<4>[    0.000000] ACPI: UEFI 0x00000000DBB89A80 000042 (v01 HPQOEM SLIC-CPC 01072009      00000000)
<4>[    0.000000] ACPI: DBGP 0x00000000DBB89AC8 000034 (v01 HPQOEM SLIC-CPC 01072009 AMI  00010013)
<7>[    0.000000] ACPI: Local APIC address 0xfee00000
<6>[    0.000000] No NUMA configuration found
<6>[    0.000000] Faking a node at [mem 0x0000000000000000-0x000000011fdfffff]
<6>[    0.000000] NODE_DATA(0) allocated [mem 0x11fdf7000-0x11fdfbfff]
<7>[    0.000000]  [ffffea0000000000-ffffea00047fffff] PMD -> [ffff88011b400000-ffff88011f3fffff] on node 0
<6>[    0.000000] Zone ranges:
<6>[    0.000000]  DMA      [mem 0x0000000000001000-0x0000000000ffffff]
<6>[    0.000000]  DMA32    [mem 0x0000000001000000-0x00000000ffffffff]
<6>[    0.000000]  Normal  [mem 0x0000000100000000-0x000000011fdfffff]
<6>[    0.000000] Movable zone start for each node
<6>[    0.000000] Early memory node ranges
<6>[    0.000000]  node  0: [mem 0x0000000000001000-0x000000000009cfff]
<6>[    0.000000]  node  0: [mem 0x0000000000100000-0x00000000c8b3bfff]
<6>[    0.000000]  node  0: [mem 0x00000000c8b43000-0x00000000c9601fff]
<6>[    0.000000]  node  0: [mem 0x00000000c98c3000-0x00000000dbaf6fff]
<6>[    0.000000]  node  0: [mem 0x00000000dbfff000-0x00000000dbffffff]
<6>[    0.000000]  node  0: [mem 0x0000000100000000-0x000000011fdfffff]
<6>[    0.000000] Initmem setup node 0 [mem 0x0000000000001000-0x000000011fdfffff]
<7>[    0.000000] On node 0 totalpages: 1029580
<7>[    0.000000]  DMA zone: 64 pages used for memmap
<7>[    0.000000]  DMA zone: 21 pages reserved
<7>[    0.000000]  DMA zone: 3996 pages, LIFO batch:0
<7>[    0.000000]  DMA32 zone: 13985 pages used for memmap
<7>[    0.000000]  DMA32 zone: 895024 pages, LIFO batch:31
<7>[    0.000000]  Normal zone: 2040 pages used for memmap
<7>[    0.000000]  Normal zone: 130560 pages, LIFO batch:31
<6>[    0.000000] Reserving Intel graphics stolen memory at 0xdd200000-0xdf1fffff
<6>[    0.000000] ACPI: PM-Timer IO Port: 0x1808
<7>[    0.000000] ACPI: Local APIC address 0xfee00000
<6>[    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] high edge lint[0x1])
<6>[    0.000000] IOAPIC[0]: apic_id 8, version 32, address 0xfec00000, GSI 0-23
<6>[    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
<6>[    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
<7>[    0.000000] ACPI: IRQ0 used by override.
<7>[    0.000000] ACPI: IRQ9 used by override.
<6>[    0.000000] Using ACPI (MADT) for SMP configuration information
<6>[    0.000000] ACPI: HPET id: 0x8086a701 base: 0xfed00000
<6>[    0.000000] smpboot: Allowing 2 CPUs, 0 hotplug CPUs
<6>[    0.000000] PM: Registered nosave memory: [mem 0x00000000-0x00000fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0x0009d000-0x0009dfff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0x0009e000-0x0009ffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0x000a0000-0x000dffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0x000e0000-0x000fffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xc8b3c000-0xc8b42fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xc9602000-0xc98c2fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdbaf7000-0xdbb5ffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdbb60000-0xdbb89fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdbb8a000-0xdbceffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdbcf0000-0xdbffefff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdc000000-0xdcffffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdd000000-0xdf1fffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xdf200000-0xf7ffffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xf8000000-0xfbffffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfc000000-0xfebfffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfec00000-0xfec00fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfec01000-0xfecfffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfed00000-0xfed03fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfed04000-0xfed1bfff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfed1c000-0xfed1ffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfed20000-0xfedfffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfee00000-0xfee00fff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xfee01000-0xfeffffff]
<6>[    0.000000] PM: Registered nosave memory: [mem 0xff000000-0xffffffff]
<6>[    0.000000] e820: [mem 0xdf200000-0xf7ffffff] available for PCI devices
<6>[    0.000000] Booting paravirtualized kernel on bare hardware
<6>[    0.000000] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645519600211568 ns
<6>[    0.000000] setup_percpu: NR_CPUS:256 nr_cpumask_bits:256 nr_cpu_ids:2 nr_node_ids:1
<6>[    0.000000] PERCPU: Embedded 33 pages/cpu @ffff88011fa00000 s96728 r8192 d30248 u1048576
<7>[    0.000000] pcpu-alloc: s96728 r8192 d30248 u1048576 alloc=1*2097152
<7>[    0.000000] pcpu-alloc: [0] 0 1
<6>[    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages: 1013470
<6>[    0.000000] Policy zone: Normal
<5>[    0.000000] Kernel command line: BOOT_IMAGE=/vmlinuz-4.2.0-16-generic root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
<6>[    0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
<7>[    0.000000] Calgary: detecting Calgary via BIOS EBDA area
<7>[    0.000000] Calgary: Unable to locate Rio Grande table in EBDA - bailing!

<6>[    0.000000] Memory: 3934776K/4118320K available (8146K kernel code, 1237K rwdata, 3800K rodata, 1460K init, 1292K bss, 183544K reserved, 0K cma-reserved)
<6>[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
<6>[    0.000000] Hierarchical RCU implementation.
<6>[    0.000000]        Build-time adjustment of leaf fanout to 64.
<6>[    0.000000]        RCU restricting CPUs from NR_CPUS=256 to nr_cpu_ids=2.
<6>[    0.000000] RCU: Adjusting geometry for rcu_fanout_leaf=64, nr_cpu_ids=2
<6>[    0.000000] NR_IRQS:16640 nr_irqs:440 16
<6>[    0.000000]        Offload RCU callbacks from all CPUs
<6>[    0.000000]        Offload RCU callbacks from CPUs: 0-1.
<6>[    0.000000] vt handoff: transparent VT on vt#7
<6>[    0.000000] Console: colour dummy device 80x25
<6>[    0.000000] console [tty0] enabled
<6>[    0.000000] clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 133484882848 ns
<7>[    0.000000] hpet clockevent registered
<6>[    0.000000] tsc: Fast TSC calibration using PIT
<6>[    0.000000] tsc: Detected 3192.511 MHz processor
<6>[    0.000023] Calibrating delay loop (skipped), value calculated using timer frequency.. 6385.02 BogoMIPS (lpj=12770044)
<6>[    0.000025] pid_max: default: 32768 minimum: 301
<6>[    0.000029] ACPI: Core revision 20150619
<4>[    0.014965] ACPI: All ACPI Tables successfully acquired
<6>[    0.014979] Security Framework initialized
<6>[    0.014987] AppArmor: AppArmor initialized
<6>[    0.014988] Yama: becoming mindful.
<6>[    0.015189] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
<6>[    0.016226] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
<6>[    0.016753] Mount-cache hash table entries: 8192 (order: 4, 65536 bytes)
<6>[    0.016758] Mountpoint-cache hash table entries: 8192 (order: 4, 65536 bytes)
<6>[    0.016939] Initializing cgroup subsys blkio
<6>[    0.016941] Initializing cgroup subsys memory
<6>[    0.016947] Initializing cgroup subsys devices
<6>[    0.016949] Initializing cgroup subsys freezer
<6>[    0.016950] Initializing cgroup subsys net_cls
<6>[    0.016952] Initializing cgroup subsys perf_event
<6>[    0.016953] Initializing cgroup subsys net_prio
<6>[    0.016955] Initializing cgroup subsys hugetlb
<6>[    0.016974] CPU: Physical Processor ID: 0
<6>[    0.016975] CPU: Processor Core ID: 0
<4>[    0.016978] ENERGY_PERF_BIAS: Set to 'normal', was 'performance'
<4>[    0.016979] ENERGY_PERF_BIAS: View and update with x86_energy_perf_policy(8)
<6>[    0.017736] mce: CPU supports 7 MCE banks
<6>[    0.017746] CPU0: Thermal monitoring enabled (TM1)
<6>[    0.017752] process: using mwait in idle threads
<6>[    0.017755] Last level iTLB entries: 4KB 1024, 2MB 1024, 4MB 1024
<6>[    0.017755] Last level dTLB entries: 4KB 1024, 2MB 1024, 4MB 1024, 1GB 4
<6>[    0.017854] Freeing SMP alternatives memory: 28K (ffffffff81ea4000 - ffffffff81eab000)
<6>[    0.019323] ftrace: allocating 30905 entries in 121 pages
<6>[    0.029805] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=0 pin2=0
<7>[    0.069524] TSC deadline timer enabled
<6>[    0.069527] smpboot: CPU0: Intel(R) Pentium(R) CPU G3250 @ 3.20GHz (fam: 06, model: 3c, stepping: 03)
<6>[    0.069548] Performance Events: PEBS fmt2+, 16-deep LBR, Haswell events, full-width counters, Intel PMU driver.
<6>[    0.069564] ... version:                3
<6>[    0.069564] ... bit width:              48
<6>[    0.069565] ... generic registers:      8
<6>[    0.069566] ... value mask:            0000ffffffffffff
<6>[    0.069566] ... max period:            0000ffffffffffff
<6>[    0.069567] ... fixed-purpose events:  3
<6>[    0.069567] ... event mask:            00000007000000ff
<6>[    0.070154] x86: Booting SMP configuration:
<6>[    0.070155] .... node  #0, CPUs:      #1
<6>[    0.074196] x86: Booted up 1 node, 2 CPUs
<6>[    0.074199] smpboot: Total of 2 processors activated (12770.04 BogoMIPS)
<6>[    0.074225] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
<6>[    0.075583] devtmpfs: initialized
<6>[    0.076915] evm: security.selinux
<6>[    0.076916] evm: security.SMACK64
<6>[    0.076917] evm: security.SMACK64EXEC
<6>[    0.076917] evm: security.SMACK64TRANSMUTE
<6>[    0.076918] evm: security.SMACK64MMAP
<6>[    0.076919] evm: security.ima
<6>[    0.076919] evm: security.capability
<6>[    0.076959] PM: Registering ACPI NVS region [mem 0xc8b3c000-0xc8b42fff] (28672 bytes)
<6>[    0.076960] PM: Registering ACPI NVS region [mem 0xdbb8a000-0xdbceffff] (1466368 bytes)
<6>[    0.077017] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
<6>[    0.077070] pinctrl core: initialized pinctrl subsystem
<6>[    0.077153] RTC time:  9:16:50, date: 03/15/16
<6>[    0.077234] NET: Registered protocol family 16
<6>[    0.086214] cpuidle: using governor ladder
<6>[    0.094226] cpuidle: using governor menu
<6>[    0.094270] ACPI FADT declares the system doesn't support PCIe ASPM, so disable it
<6>[    0.094271] ACPI: bus type PCI registered
<6>[    0.094273] acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5
<6>[    0.094316] PCI: MMCONFIG for domain 0000 [bus 00-3f] at [mem 0xf8000000-0xfbffffff] (base 0xf8000000)
<6>[    0.094317] PCI: MMCONFIG at [mem 0xf8000000-0xfbffffff] reserved in E820
<6>[    0.094324] PCI: Using configuration type 1 for base access
<6>[    0.094457] NMI watchdog: enabled on all CPUs, permanently consumes one hw-PMU counter.
<6>[    0.094464] perf_event_intel: PMU erratum BJ122, BV98, HSD29 workaround disabled, HT off
<6>[    0.102452] ACPI: Added _OSI(Module Device)
<6>[    0.102453] ACPI: Added _OSI(Processor Device)
<6>[    0.102454] ACPI: Added _OSI(3.0 _SCP Extensions)
<6>[    0.102455] ACPI: Added _OSI(Processor Aggregator Device)
<4>[    0.105924] ACPI: Executed 6 blocks of module-level executable AML code
<4>[    0.110042] ACPI: Dynamic OEM Table Load:
<4>[    0.110047] ACPI: SSDT 0xFFFF88011A5B5400 0003D3 (v02 HPQOEM SLIC-CPC 00003001 INTL 20051117)
<4>[    0.110604] ACPI: Dynamic OEM Table Load:
<4>[    0.110608] ACPI: SSDT 0xFFFF88011B016800 0005AA (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
<4>[    0.111197] ACPI: Dynamic OEM Table Load:
<4>[    0.111199] ACPI: SSDT 0xFFFF88011A5D7000 000119 (v02 HPQOEM SLIC-CPC 00003000 INTL 20051117)
<6>[    0.111818] ACPI: Interpreter enabled
<4>[    0.111825] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S1_] (20150619/hwxface-580)
<4>[    0.111830] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S2_] (20150619/hwxface-580)
<6>[    0.111847] ACPI: (supports S0 S3 S4 S5)
<6>[    0.111848] ACPI: Using IOAPIC for interrupt routing
<6>[    0.111870] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
<6>[    0.112204] ACPI: Power Resource [PG00] (on)
<6>[    0.112400] ACPI: Power Resource [PG01] (on)
<6>[    0.112590] ACPI: Power Resource [PG02] (on)
<6>[    0.114960] ACPI: Power Resource [WRST] (off)
<6>[    0.115137] ACPI: Power Resource [WRST] (off)
<6>[    0.115314] ACPI: Power Resource [WRST] (off)
<6>[    0.115502] ACPI: Power Resource [WRST] (off)
<6>[    0.115672] ACPI: Power Resource [WRST] (off)
<6>[    0.115844] ACPI: Power Resource [WRST] (off)
<6>[    0.116013] ACPI: Power Resource [WRST] (off)
<6>[    0.116183] ACPI: Power Resource [WRST] (off)
<6>[    0.118300] ACPI: Power Resource [FN00] (off)
<6>[    0.118351] ACPI: Power Resource [FN01] (off)
<6>[    0.118399] ACPI: Power Resource [FN02] (off)
<6>[    0.118447] ACPI: Power Resource [FN03] (off)
<6>[    0.118495] ACPI: Power Resource [FN04] (off)
<6>[    0.119083] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-3e])
<6>[    0.119088] acpi PNP0A08:00: _OSC: OS supports [ExtendedConfig ASPM ClockPM Segments MSI]
<6>[    0.119556] acpi PNP0A08:00: _OSC: OS now controls [PCIeHotplug PME AER PCIeCapability]
<6>[    0.119557] acpi PNP0A08:00: FADT indicates ASPM is unsupported, using BIOS configuration
<6>[    0.119701] acpi PNP0A08:00: host bridge window expanded to [mem 0xdf200000-0xfeafffff window]; [mem 0xfe101000-0xfe113fff window] ignored
<6>[    0.119832] PCI host bridge to bus 0000:00
<6>[    0.119834] pci_bus 0000:00: root bus resource [bus 00-3e]
<6>[    0.119835] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7 window]
<6>[    0.119836] pci_bus 0000:00: root bus resource [io  0x0d00-0xffff window]
<6>[    0.119837] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff window]
<6>[    0.119838] pci_bus 0000:00: root bus resource [mem 0x000d0000-0x000d3fff window]
<6>[    0.119839] pci_bus 0000:00: root bus resource [mem 0x000d4000-0x000d7fff window]
<6>[    0.119840] pci_bus 0000:00: root bus resource [mem 0x000d8000-0x000dbfff window]
<6>[    0.119841] pci_bus 0000:00: root bus resource [mem 0x000dc000-0x000dffff window]
<6>[    0.119842] pci_bus 0000:00: root bus resource [mem 0x000e0000-0x000e3fff window]
<6>[    0.119843] pci_bus 0000:00: root bus resource [mem 0x000e4000-0x000e7fff window]
<6>[    0.119844] pci_bus 0000:00: root bus resource [mem 0xdf200000-0xfeafffff window]
<7>[    0.119850] pci 0000:00:00.0: [8086:0c00] type 00 class 0x060000
<7>[    0.119911] pci 0000:00:01.0: [8086:0c01] type 01 class 0x060400
<7>[    0.119935] pci 0000:00:01.0: PME# supported from D0 D3hot D3cold
<6>[    0.119984] pci 0000:00:01.0: System wakeup disabled by ACPI
<7>[    0.120012] pci 0000:00:02.0: [8086:0402] type 00 class 0x030000
<7>[    0.120022] pci 0000:00:02.0: reg 0x10: [mem 0xf7800000-0xf7bfffff 64bit]
<7>[    0.120026] pci 0000:00:02.0: reg 0x18: [mem 0xe0000000-0xefffffff 64bit pref]
<7>[    0.120030] pci 0000:00:02.0: reg 0x20: [io  0xf000-0xf03f]
<7>[    0.120112] pci 0000:00:14.0: [8086:8c31] type 00 class 0x0c0330
<7>[    0.120136] pci 0000:00:14.0: reg 0x10: [mem 0xf7d00000-0xf7d0ffff 64bit]
<7>[    0.120179] pci 0000:00:14.0: PME# supported from D3hot D3cold
<6>[    0.120210] pci 0000:00:14.0: System wakeup disabled by ACPI
<7>[    0.120237] pci 0000:00:16.0: [8086:8c3a] type 00 class 0x078000
<7>[    0.120261] pci 0000:00:16.0: reg 0x10: [mem 0xf7d15000-0xf7d1500f 64bit]
<7>[    0.120306] pci 0000:00:16.0: PME# supported from D0 D3hot D3cold
<7>[    0.120381] pci 0000:00:1a.0: [8086:8c2d] type 00 class 0x0c0320
<7>[    0.120406] pci 0000:00:1a.0: reg 0x10: [mem 0xf7d13000-0xf7d133ff]
<7>[    0.120466] pci 0000:00:1a.0: PME# supported from D0 D3hot D3cold
<6>[    0.120498] pci 0000:00:1a.0: System wakeup disabled by ACPI
<7>[    0.120525] pci 0000:00:1c.0: [8086:8c10] type 01 class 0x060400
<7>[    0.120577] pci 0000:00:1c.0: PME# supported from D0 D3hot D3cold
<6>[    0.120632] pci 0000:00:1c.0: System wakeup disabled by ACPI
<7>[    0.120659] pci 0000:00:1c.3: [8086:8c16] type 01 class 0x060400
<7>[    0.120711] pci 0000:00:1c.3: PME# supported from D0 D3hot D3cold
<6>[    0.120765] pci 0000:00:1c.3: System wakeup disabled by ACPI
<7>[    0.120795] pci 0000:00:1d.0: [8086:8c26] type 00 class 0x0c0320
<7>[    0.120820] pci 0000:00:1d.0: reg 0x10: [mem 0xf7d12000-0xf7d123ff]
<7>[    0.120880] pci 0000:00:1d.0: PME# supported from D0 D3hot D3cold
<6>[    0.120913] pci 0000:00:1d.0: System wakeup disabled by ACPI
<7>[    0.120941] pci 0000:00:1f.0: [8086:8c5c] type 00 class 0x060100
<7>[    0.121072] pci 0000:00:1f.2: [8086:8c02] type 00 class 0x010601
<7>[    0.121090] pci 0000:00:1f.2: reg 0x10: [io  0xf0b0-0xf0b7]
<7>[    0.121097] pci 0000:00:1f.2: reg 0x14: [io  0xf0a0-0xf0a3]
<7>[    0.121104] pci 0000:00:1f.2: reg 0x18: [io  0xf090-0xf097]
<7>[    0.121110] pci 0000:00:1f.2: reg 0x1c: [io  0xf080-0xf083]
<7>[    0.121117] pci 0000:00:1f.2: reg 0x20: [io  0xf060-0xf07f]
<7>[    0.121124] pci 0000:00:1f.2: reg 0x24: [mem 0xf7d11000-0xf7d117ff]
<7>[    0.121145] pci 0000:00:1f.2: PME# supported from D3hot
<7>[    0.121192] pci 0000:00:1f.3: [8086:8c22] type 00 class 0x0c0500
<7>[    0.121206] pci 0000:00:1f.3: reg 0x10: [mem 0xf7d10000-0xf7d100ff 64bit]
<7>[    0.121223] pci 0000:00:1f.3: reg 0x20: [io  0xf040-0xf05f]
<6>[    0.121302] pci 0000:00:01.0: PCI bridge to [bus 01]
<6>[    0.121347] pci 0000:00:1c.0: PCI bridge to [bus 02]
<7>[    0.121407] pci 0000:03:00.0: [10ec:8168] type 00 class 0x020000
<7>[    0.121445] pci 0000:03:00.0: reg 0x10: [io  0xe000-0xe0ff]
<7>[    0.121472] pci 0000:03:00.0: reg 0x18: [mem 0xf7c00000-0xf7c00fff 64bit]
<7>[    0.121488] pci 0000:03:00.0: reg 0x20: [mem 0xf0000000-0xf0003fff 64bit pref]
<7>[    0.121545] pci 0000:03:00.0: supports D1 D2
<7>[    0.121546] pci 0000:03:00.0: PME# supported from D0 D1 D2 D3hot D3cold
<6>[    0.121590] pci 0000:03:00.0: System wakeup disabled by ACPI
<6>[    0.126297] pci 0000:00:1c.3: PCI bridge to [bus 03]
<7>[    0.126300] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
<7>[    0.126303] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
<7>[    0.126308] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
<6>[    0.126957] ACPI: PCI Interrupt Link [LNKA] (IRQs 3 4 5 6 10 *11 12 14 15)
<6>[    0.126991] ACPI: PCI Interrupt Link [LNKB] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
<6>[    0.127026] ACPI: PCI Interrupt Link [LNKC] (IRQs *3 4 5 6 10 11 12 14 15)
<6>[    0.127059] ACPI: PCI Interrupt Link [LNKD] (IRQs 3 4 5 6 *10 11 12 14 15)
<6>[    0.127090] ACPI: PCI Interrupt Link [LNKE] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
<6>[    0.127122] ACPI: PCI Interrupt Link [LNKF] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
<6>[    0.127154] ACPI: PCI Interrupt Link [LNKG] (IRQs 3 4 5 6 10 11 12 14 15) *0, disabled.
<6>[    0.127187] ACPI: PCI Interrupt Link [LNKH] (IRQs 3 4 *5 6 10 11 12 14 15)

<4>[    0.127396] ACPI: Enabled 6 GPEs in block 00 to 3F
<6>[    0.127480] vgaarb: setting as boot device: PCI:0000:00:02.0
<6>[    0.127481] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
<6>[    0.127482] vgaarb: loaded
<6>[    0.127483] vgaarb: bridge control possible 0000:00:02.0
<5>[    0.127662] SCSI subsystem initialized
<7>[    0.127693] libata version 3.00 loaded.
<6>[    0.127708] ACPI: bus type USB registered
<6>[    0.127721] usbcore: registered new interface driver usbfs
<6>[    0.127728] usbcore: registered new interface driver hub
<6>[    0.127734] usbcore: registered new device driver usb
<6>[    0.127827] PCI: Using ACPI for IRQ routing
<7>[    0.129079] PCI: pci_cache_line_size set to 64 bytes
<7>[    0.129108] e820: reserve RAM buffer [mem 0x0009d800-0x0009ffff]
<7>[    0.129109] e820: reserve RAM buffer [mem 0xc8b3c000-0xcbffffff]
<7>[    0.129110] e820: reserve RAM buffer [mem 0xc9602000-0xcbffffff]
<7>[    0.129110] e820: reserve RAM buffer [mem 0xdbaf7000-0xdbffffff]
<7>[    0.129111] e820: reserve RAM buffer [mem 0x11fe00000-0x11fffffff]
<6>[    0.129189] NetLabel: Initializing
<6>[    0.129190] NetLabel:  domain hash size = 128
<6>[    0.129190] NetLabel:  protocols = UNLABELED CIPSOv4
<6>[    0.129199] NetLabel:  unlabeled traffic allowed by default
<6>[    0.129251] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0, 0, 0, 0, 0, 0
<6>[    0.129254] hpet0: 8 comparators, 64-bit 14.318180 MHz counter
<6>[    0.131276] clocksource: Switched to clocksource hpet
<6>[    0.135704] AppArmor: AppArmor Filesystem Enabled
<6>[    0.135764] pnp: PnP ACPI init
<6>[    0.135935] system 00:00: [io  0x0800-0x087f] has been reserved
<7>[    0.135938] system 00:00: Plug and Play ACPI device, IDs PNP0c02 (active)
<7>[    0.135957] pnp 00:01: Plug and Play ACPI device, IDs PNP0b00 (active)
<6>[    0.135982] system 00:02: [io  0x1854-0x1857] has been reserved
<7>[    0.135984] system 00:02: Plug and Play ACPI device, IDs INT3f0d PNP0c02 (active)
<6>[    0.136121] system 00:03: [io  0x0a00-0x0a1f] has been reserved
<6>[    0.136122] system 00:03: [io  0x0a20-0x0a2f] has been reserved
<6>[    0.136123] system 00:03: [io  0x0a30-0x0a3f] has been reserved
<6>[    0.136124] system 00:03: [io  0x0a40-0x0a7f] has been reserved
<6>[    0.136125] system 00:03: [io  0x0a50-0x0a5f] has been reserved
<7>[    0.136127] system 00:03: Plug and Play ACPI device, IDs PNP0c02 (active)
<6>[    0.136174] system 00:04: [io  0x04d0-0x04d1] has been reserved
<7>[    0.136176] system 00:04: Plug and Play ACPI device, IDs PNP0c02 (active)
<7>[    0.136304] pnp 00:05: Plug and Play ACPI device, IDs PNP0c31 (active)
<6>[    0.136504] system 00:06: [mem 0xfed1c000-0xfed1ffff] has been reserved
<6>[    0.136506] system 00:06: [mem 0xfed10000-0xfed17fff] has been reserved
<6>[    0.136507] system 00:06: [mem 0xfed18000-0xfed18fff] has been reserved
<6>[    0.136508] system 00:06: [mem 0xfed19000-0xfed19fff] has been reserved
<6>[    0.136509] system 00:06: [mem 0xf8000000-0xfbffffff] has been reserved
<6>[    0.136510] system 00:06: [mem 0xfed20000-0xfed3ffff] has been reserved
<6>[    0.136511] system 00:06: [mem 0xfed90000-0xfed93fff] has been reserved
<6>[    0.136512] system 00:06: [mem 0xfed45000-0xfed8ffff] has been reserved
<6>[    0.136514] system 00:06: [mem 0xff000000-0xffffffff] has been reserved
<6>[    0.136515] system 00:06: [mem 0xfee00000-0xfeefffff] could not be reserved
<6>[    0.136516] system 00:06: [mem 0xf7fe0000-0xf7feffff] has been reserved
<6>[    0.136517] system 00:06: [mem 0xf7ff0000-0xf7ffffff] has been reserved
<7>[    0.136519] system 00:06: Plug and Play ACPI device, IDs PNP0c02 (active)
<6>[    0.136648] pnp: PnP ACPI: found 7 devices
<6>[    0.142525] clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns
<7>[    0.142541] pci 0000:00:1c.0: bridge window [io  0x1000-0x0fff] to [bus 02] add_size 1000
<7>[    0.142542] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff 64bit pref] to [bus 02] add_size 200000 add_align 100000
<7>[    0.142544] pci 0000:00:1c.0: bridge window [mem 0x00100000-0x000fffff] to [bus 02] add_size 200000 add_align 100000
<7>[    0.142552] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x000fffff] res_to_dev_res add_size 200000 min_align 100000
<7>[    0.142553] pci 0000:00:1c.0: res[14]=[mem 0x00100000-0x002fffff] res_to_dev_res add_size 200000 min_align 100000
<7>[    0.142554] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x000fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
<7>[    0.142556] pci 0000:00:1c.0: res[15]=[mem 0x00100000-0x002fffff 64bit pref] res_to_dev_res add_size 200000 min_align 100000
<7>[    0.142557] pci 0000:00:1c.0: res[13]=[io  0x1000-0x0fff] res_to_dev_res add_size 1000 min_align 1000
<7>[    0.142558] pci 0000:00:1c.0: res[13]=[io  0x1000-0x1fff] res_to_dev_res add_size 1000 min_align 1000
<6>[    0.142562] pci 0000:00:1c.0: BAR 14: assigned [mem 0xdf200000-0xdf3fffff]
<6>[    0.142567] pci 0000:00:1c.0: BAR 15: assigned [mem 0xdf400000-0xdf5fffff 64bit pref]
<6>[    0.142569] pci 0000:00:1c.0: BAR 13: assigned [io  0x2000-0x2fff]
<6>[    0.142570] pci 0000:00:01.0: PCI bridge to [bus 01]
<6>[    0.142575] pci 0000:00:1c.0: PCI bridge to [bus 02]
<6>[    0.142577] pci 0000:00:1c.0:  bridge window [io  0x2000-0x2fff]
<6>[    0.142581] pci 0000:00:1c.0:  bridge window [mem 0xdf200000-0xdf3fffff]
<6>[    0.142585] pci 0000:00:1c.0:  bridge window [mem 0xdf400000-0xdf5fffff 64bit pref]
<6>[    0.142590] pci 0000:00:1c.3: PCI bridge to [bus 03]
<6>[    0.142592] pci 0000:00:1c.3:  bridge window [io  0xe000-0xefff]
<6>[    0.142596] pci 0000:00:1c.3:  bridge window [mem 0xf7c00000-0xf7cfffff]
<6>[    0.142599] pci 0000:00:1c.3:  bridge window [mem 0xf0000000-0xf00fffff 64bit pref]
<7>[    0.142605] pci_bus 0000:00: resource 4 [io  0x0000-0x0cf7 window]
<7>[    0.142606] pci_bus 0000:00: resource 5 [io  0x0d00-0xffff window]
<7>[    0.142607] pci_bus 0000:00: resource 6 [mem 0x000a0000-0x000bffff window]
<7>[    0.142608] pci_bus 0000:00: resource 7 [mem 0x000d0000-0x000d3fff window]
<7>[    0.142609] pci_bus 0000:00: resource 8 [mem 0x000d4000-0x000d7fff window]
<7>[    0.142610] pci_bus 0000:00: resource 9 [mem 0x000d8000-0x000dbfff window]
<7>[    0.142611] pci_bus 0000:00: resource 10 [mem 0x000dc000-0x000dffff window]
<7>[    0.142612] pci_bus 0000:00: resource 11 [mem 0x000e0000-0x000e3fff window]
<7>[    0.142613] pci_bus 0000:00: resource 12 [mem 0x000e4000-0x000e7fff window]
<7>[    0.142614] pci_bus 0000:00: resource 13 [mem 0xdf200000-0xfeafffff window]
<7>[    0.142615] pci_bus 0000:02: resource 0 [io  0x2000-0x2fff]
<7>[    0.142616] pci_bus 0000:02: resource 1 [mem 0xdf200000-0xdf3fffff]
<7>[    0.142617] pci_bus 0000:02: resource 2 [mem 0xdf400000-0xdf5fffff 64bit pref]
<7>[    0.142618] pci_bus 0000:03: resource 0 [io  0xe000-0xefff]
<7>[    0.142619] pci_bus 0000:03: resource 1 [mem 0xf7c00000-0xf7cfffff]
<7>[    0.142620] pci_bus 0000:03: resource 2 [mem 0xf0000000-0xf00fffff 64bit pref]
<6>[    0.142643] NET: Registered protocol family 2
<6>[    0.142754] TCP established hash table entries: 32768 (order: 6, 262144 bytes)
<6>[    0.142834] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
<6>[    0.142951] TCP: Hash tables configured (established 32768 bind 32768)
<6>[    0.142973] UDP hash table entries: 2048 (order: 4, 65536 bytes)
<6>[    0.142989] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
<6>[    0.143027] NET: Registered protocol family 1
<7>[    0.143039] pci 0000:00:02.0: Video device with shadowed ROM
<7>[    0.183393] PCI: CLS 64 bytes, default 64
<6>[    0.183435] Trying to unpack rootfs image as initramfs...
<6>[    0.568375] Freeing initrd memory: 34976K (ffff880033ba0000 - ffff880035dc8000)
<6>[    0.568411] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
<6>[    0.568413] software IO TLB [mem 0xd7af7000-0xdbaf7000] (64MB) mapped at [ffff8800d7af7000-ffff8800dbaf6fff]
<6>[    0.568470] RAPL PMU detected, API unit is 2^-32 Joules, 4 fixed counters 655360 ms ovfl timer
<6>[    0.568471] hw unit of domain pp0-core 2^-14 Joules
<6>[    0.568472] hw unit of domain package 2^-14 Joules
<6>[    0.568472] hw unit of domain dram 2^-14 Joules
<6>[    0.568473] hw unit of domain pp1-gpu 2^-14 Joules
<6>[    0.568565] microcode: CPU0 sig=0x306c3, pf=0x2, revision=0x1d
<6>[    0.568570] microcode: CPU1 sig=0x306c3, pf=0x2, revision=0x1d
<6>[    0.568617] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
<6>[    0.568673] Scanning for low memory corruption every 60 seconds
<6>[    0.568895] futex hash table entries: 512 (order: 3, 32768 bytes)
<5>[    0.568911] Initialise system trusted keyring
<6>[    0.568929] audit: initializing netlink subsys (disabled)
<5>[    0.568942] audit: type=2000 audit(1458033410.568:1): initialized
<6>[    0.569190] HugeTLB registered 1 GB page size, pre-allocated 0 pages
<6>[    0.569191] HugeTLB registered 2 MB page size, pre-allocated 0 pages
<6>[    0.570111] zpool: loaded
<6>[    0.570114] zbud: loaded
<5>[    0.570242] VFS: Disk quotas dquot_6.6.0
<6>[    0.570267] VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
<6>[    0.570591] fuse init (API version 7.23)
<5>[    0.570685] Key type big_key registered
<5>[    0.570937] Key type asymmetric registered
<5>[    0.570940] Asymmetric key parser 'x509' registered
<6>[    0.570950] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 249)
<6>[    0.570970] io scheduler noop registered
<6>[    0.570972] io scheduler deadline registered (default)
<6>[    0.570992] io scheduler cfq registered
<6>[    0.571386] pcieport 0000:00:01.0: Signaling PME through PCIe PME interrupt
<7>[    0.571389] pcie_pme 0000:00:01.0:pcie01: service driver pcie_pme loaded
<6>[    0.571404] pcieport 0000:00:1c.0: Signaling PME through PCIe PME interrupt
<7>[    0.571407] pcie_pme 0000:00:1c.0:pcie01: service driver pcie_pme loaded
<6>[    0.571421] pcieport 0000:00:1c.3: Signaling PME through PCIe PME interrupt
<6>[    0.571422] pci 0000:03:00.0: Signaling PME through PCIe PME interrupt

<7>[    0.571426] pcie_pme 0000:00:1c.3:pcie01: service driver pcie_pme loaded
<6>[    0.571431] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
<6>[    0.571439] pciehp 0000:00:1c.0:pcie04: Slot #0 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ LLActRep+
<7>[    0.571456] pciehp 0000:00:1c.0:pcie04: service driver pciehp loaded
<6>[    0.571458] pciehp: PCI Express Hot Plug Controller Driver version: 0.4
<6>[    0.571479] vesafb: mode is 1920x1080x32, linelength=7680, pages=0
<6>[    0.571480] vesafb: scrolling: redraw
<6>[    0.571481] vesafb: Truecolor: size=8:8:8:8, shift=24:16:8:0
<6>[    0.571488] vesafb: framebuffer at 0xe0000000, mapped to 0xffffc90000800000, using 8128k, total 8128k
<6>[    0.571561] Console: switching to colour frame buffer device 240x67
<6>[    0.571577] fb0: VESA VGA frame buffer device
<7>[    0.571589] intel_idle: MWAIT substates: 0x2120
<7>[    0.571590] intel_idle: v0.4 model 0x3C
<7>[    0.571590] intel_idle: lapic_timer_reliable_states 0xffffffff
<6>[    0.571713] input: Power Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input0
<6>[    0.571716] ACPI: Power Button [PWRB]
<6>[    0.571740] input: Sleep Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1
<6>[    0.571742] ACPI: Sleep Button [SLPB]
<6>[    0.571765] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input2
<6>[    0.571766] ACPI: Power Button [PWRF]
<6>[    0.572243] thermal LNXTHERM:00: registered as thermal_zone0
<6>[    0.572245] ACPI: Thermal Zone [TZ00] (28 C)
<6>[    0.572366] thermal LNXTHERM:01: registered as thermal_zone1
<6>[    0.572367] ACPI: Thermal Zone [TZ01] (30 C)
<6>[    0.572411] GHES: HEST is not enabled!
<6>[    0.572467] Serial: 8250/16550 driver, 32 ports, IRQ sharing enabled
<6>[    0.573557] Linux agpgart interface v0.103
<6>[    0.647751] tpm_tis 00:05: 1.2 TPM (device-id 0xB, rev-id 16)
<6>[    0.937858] brd: module loaded
<6>[    0.938377] loop: module loaded
<6>[    0.938514] libphy: Fixed MDIO Bus: probed
<6>[    0.938516] tun: Universal TUN/TAP device driver, 1.6
<6>[    0.938516] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
<6>[    0.938543] PPP generic driver version 2.4.2
<6>[    0.938661] xhci_hcd 0000:00:14.0: xHCI Host Controller
<6>[    0.938665] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 1
<6>[    0.938742] xhci_hcd 0000:00:14.0: hcc params 0x200077c1 hci version 0x100 quirks 0x00009810
<7>[    0.938747] xhci_hcd 0000:00:14.0: cache line size of 64 is not supported
<6>[    0.938813] usb usb1: New USB device found, idVendor=1d6b, idProduct=0002
<6>[    0.938814] usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1
<6>[    0.938815] usb usb1: Product: xHCI Host Controller
<6>[    0.938816] usb usb1: Manufacturer: Linux 4.2.0-16-generic xhci-hcd
<6>[    0.938817] usb usb1: SerialNumber: 0000:00:14.0
<6>[    0.938890] hub 1-0:1.0: USB hub found
<6>[    0.938900] hub 1-0:1.0: 10 ports detected
<6>[    0.940551] xhci_hcd 0000:00:14.0: xHCI Host Controller
<6>[    0.940553] xhci_hcd 0000:00:14.0: new USB bus registered, assigned bus number 2
<6>[    0.940575] usb usb2: New USB device found, idVendor=1d6b, idProduct=0003
<6>[    0.940576] usb usb2: New USB device strings: Mfr=3, Product=2, SerialNumber=1
<6>[    0.940577] usb usb2: Product: xHCI Host Controller
<6>[    0.940578] usb usb2: Manufacturer: Linux 4.2.0-16-generic xhci-hcd
<6>[    0.940579] usb usb2: SerialNumber: 0000:00:14.0
<6>[    0.940657] hub 2-0:1.0: USB hub found
<6>[    0.940662] hub 2-0:1.0: 2 ports detected
<6>[    0.941069] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
<6>[    0.941073] ehci-pci: EHCI PCI platform driver
<6>[    0.941134] ehci-pci 0000:00:1a.0: EHCI Host Controller
<6>[    0.941137] ehci-pci 0000:00:1a.0: new USB bus registered, assigned bus number 3
<6>[    0.941146] ehci-pci 0000:00:1a.0: debug port 2
<7>[    0.945032] ehci-pci 0000:00:1a.0: cache line size of 64 is not supported
<6>[    0.945039] ehci-pci 0000:00:1a.0: irq 16, io mem 0xf7d13000
<6>[    0.959985] ehci-pci 0000:00:1a.0: USB 2.0 started, EHCI 1.00
<6>[    0.960014] usb usb3: New USB device found, idVendor=1d6b, idProduct=0002
<6>[    0.960015] usb usb3: New USB device strings: Mfr=3, Product=2, SerialNumber=1
<6>[    0.960016] usb usb3: Product: EHCI Host Controller
<6>[    0.960017] usb usb3: Manufacturer: Linux 4.2.0-16-generic ehci_hcd
<6>[    0.960018] usb usb3: SerialNumber: 0000:00:1a.0
<6>[    0.960141] hub 3-0:1.0: USB hub found
<6>[    0.960145] hub 3-0:1.0: 2 ports detected
<6>[    0.960279] ehci-pci 0000:00:1d.0: EHCI Host Controller
<6>[    0.960283] ehci-pci 0000:00:1d.0: new USB bus registered, assigned bus number 4
<6>[    0.960292] ehci-pci 0000:00:1d.0: debug port 2
<7>[    0.964180] ehci-pci 0000:00:1d.0: cache line size of 64 is not supported
<6>[    0.964187] ehci-pci 0000:00:1d.0: irq 23, io mem 0xf7d12000
<6>[    0.976001] ehci-pci 0000:00:1d.0: USB 2.0 started, EHCI 1.00
<6>[    0.976030] usb usb4: New USB device found, idVendor=1d6b, idProduct=0002
<6>[    0.976031] usb usb4: New USB device strings: Mfr=3, Product=2, SerialNumber=1
<6>[    0.976032] usb usb4: Product: EHCI Host Controller
<6>[    0.976033] usb usb4: Manufacturer: Linux 4.2.0-16-generic ehci_hcd
<6>[    0.976034] usb usb4: SerialNumber: 0000:00:1d.0
<6>[    0.976153] hub 4-0:1.0: USB hub found
<6>[    0.976157] hub 4-0:1.0: 2 ports detected
<6>[    0.976235] ehci-platform: EHCI generic platform driver
<6>[    0.976242] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
<6>[    0.976245] ohci-pci: OHCI PCI platform driver
<6>[    0.976251] ohci-platform: OHCI generic platform driver
<6>[    0.976256] uhci_hcd: USB Universal Host Controller Interface driver
<6>[    0.976291] i8042: PNP: No PS/2 controller found. Probing ports directly.
<6>[    0.976706] serio: i8042 KBD port at 0x60,0x64 irq 1
<6>[    0.976710] serio: i8042 AUX port at 0x60,0x64 irq 12
<6>[    0.976911] mousedev: PS/2 mouse device common for all mice
<6>[    0.977191] rtc_cmos 00:01: RTC can wake from S4
<6>[    0.977296] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0
<6>[    0.977319] rtc_cmos 00:01: alarms up to one month, y3k, 242 bytes nvram, hpet irqs
<6>[    0.977325] i2c /dev entries driver
<6>[    0.977376] device-mapper: uevent: version 1.0.3
<6>[    0.977433] device-mapper: ioctl: 4.33.0-ioctl (2015-8-18) initialised: dm-devel@redhat.com
<6>[    0.977445] Intel P-state driver initializing.
<6>[    0.977533] ledtrig-cpu: registered to indicate activity on CPUs
<4>[    0.977799] PCCT header not found.
<6>[    0.978299] NET: Registered protocol family 10
<6>[    0.978721] NET: Registered protocol family 17
<5>[    0.978748] Key type dns_resolver registered
<5>[    0.979451] Loading compiled-in X.509 certificates
<5>[    0.981717] Loaded X.509 cert 'Build time autogenerated kernel key: 6a1c9c21f04ab86fd1d7ced6ca113540fc8e35b6'
<6>[    0.981754] registered taskstats version 1
<6>[    0.981805] zswap: loading zswap
<6>[    0.981810] zswap: using zbud pool
<6>[    0.981820] zswap: using lzo compressor
<5>[    0.984586] Key type trusted registered
<5>[    0.986552] Key type encrypted registered
<6>[    0.986558] AppArmor: AppArmor sha1 policy hashing enabled
<6>[    1.252224] usb 1-1: new low-speed USB device number 2 using xhci_hcd
<6>[    1.272241] usb 3-1: new high-speed USB device number 2 using ehci-pci
<6>[    1.288251] usb 4-1: new high-speed USB device number 2 using ehci-pci
<6>[    1.383961] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[    1.383972] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[    1.383973] usb 1-1: Product: HP USB Optical Mouse
<6>[    1.383974] usb 1-1: Manufacturer: PixArt
<4>[    1.384084] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[    1.404752] usb 3-1: New USB device found, idVendor=8087, idProduct=8008
<6>[    1.404754] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
<6>[    1.405033] hub 3-1:1.0: USB hub found
<6>[    1.405131] hub 3-1:1.0: 4 ports detected
<6>[    1.420765] usb 4-1: New USB device found, idVendor=8087, idProduct=8000
<6>[    1.420768] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0
<6>[    1.421045] hub 4-1:1.0: USB hub found
<6>[    1.421143] hub 4-1:1.0: 6 ports detected
<6>[    1.496418] usb 1-2: new low-speed USB device number 3 using xhci_hcd
<6>[    1.568478] tsc: Refined TSC clocksource calibration: 3192.607 MHz
<6>[    1.568480] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x2e0501eb3d1, max_idle_ns: 440795254769 ns
<6>[    1.629887] usb 1-2: New USB device found, idVendor=0461, idProduct=0010
<6>[    1.629890] usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[    1.629891] usb 1-2: Product: USB Keyboard
<6>[    1.629892] usb 1-2: Manufacturer: NOVATEK
<4>[    1.630022] usb 1-2: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<4>[    1.630025] usb 1-2: ep 0x82 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[    1.704646] evm: HMAC attrs: 0x1
<6>[    1.704966]  Magic number: 8:779:272
<6>[    1.705075] rtc_cmos 00:01: setting system clock to 2016-03-15 09:16:52 UTC (1458033412)
<6>[    1.705108] BIOS EDD facility v0.16 2004-Jun-25, 0 devices found
<6>[    1.705108] EDD information not available.
<7>[    1.705164] PM: Hibernation image not present or could not be loaded.
<6>[    1.705380] Freeing unused kernel memory: 1460K (ffffffff81d37000 - ffffffff81ea4000)
<6>[    1.705381] Write protecting the kernel read-only data: 12288k
<6>[    1.705491] Freeing unused kernel memory: 36K (ffff8800017f7000 - ffff880001800000)
<6>[    1.705543] Freeing unused kernel memory: 296K (ffff880001bb6000 - ffff880001c00000)
<5>[    1.717786] random: systemd-udevd urandom read with 4 bits of entropy available
<6>[    1.746626] hidraw: raw HID events driver (C) Jiri Kosina
<6>[    1.758355] [drm] Initialized drm 1.1.0 20060810
<6>[    1.758467] usbcore: registered new interface driver usbhid
<6>[    1.758468] usbhid: USB HID core driver
<6>[    1.765791] wmi: Mapper loaded
<6>[    1.770126] r8169 Gigabit Ethernet driver 2.3LK-NAPI loaded
<4>[    1.770138] r8169 0000:03:00.0: can't disable ASPM; OS doesn't have ASPM control
<6>[    1.773502] [drm] Memory usable by graphics device = 2048M
<7>[    1.773505] checking generic (e0000000 7f0000) vs hw (e0000000 10000000)
<6>[    1.773506] fb: switching to inteldrmfb from VESA VGA
<6>[    1.773529] Console: switching to colour dummy device 80x25
<6>[    1.773873] [drm] Replacing VGA console driver
<6>[    1.778413] r8169 0000:03:00.0 eth0: RTL8168g/8111g at 0xffffc9000001e000, 48:0f:cf:36:52:2a, XID 0c000800 IRQ 28
<6>[    1.778415] r8169 0000:03:00.0 eth0: jumbo features [frames: 9200 bytes, tx checksumming: ko]
<6>[    1.784200] [drm] Supports vblank timestamp caching Rev 2 (21.10.2013).
<6>[    1.784203] [drm] Driver supports precise vblank timestamp query.
<6>[    1.784300] vgaarb: device changed decodes: PCI:0000:00:02.0,olddecodes=io+mem,decodes=io+mem:owns=io+mem
<6>[    1.791085] ACPI: Video Device [GFX0] (multi-head: yes  rom: no  post: no)
<6>[    1.791226] input: Video Bus as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A08:00/LNXVIDEO:00/input/input6
<6>[    1.791293] [drm] Initialized i915 1.6.0 20150522 for 0000:00:02.0 on minor 0
<7>[    1.791314] ahci 0000:00:1f.2: version 3.0
<6>[    1.791435] ahci 0000:00:1f.2: AHCI 0001.0300 32 slots 4 ports 6 Gbps 0x11 impl SATA mode
<6>[    1.791438] ahci 0000:00:1f.2: flags: 64bit ncq pm led clo pio slum part ems
<6>[    1.797758] scsi host0: ahci
<6>[    1.797821] scsi host1: ahci
<6>[    1.797868] scsi host2: ahci
<6>[    1.797912] scsi host3: ahci
<6>[    1.797955] scsi host4: ahci
<6>[    1.797981] ata1: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11100 irq 30
<6>[    1.797982] ata2: DUMMY
<6>[    1.797983] ata3: DUMMY
<6>[    1.797984] ata4: DUMMY
<6>[    1.797986] ata5: SATA max UDMA/133 abar m2048@0xf7d11000 port 0xf7d11300 irq 30
<6>[    1.813022] fbcon: inteldrmfb (fb0) is primary device
<6>[    1.813071] Console: switching to colour frame buffer device 240x67
<6>[    1.813088] i915 0000:00:02.0: fb0: inteldrmfb frame buffer device
<6>[    1.813089] i915 0000:00:02.0: registered panic notifier
<6>[    1.821832] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0001/input/input7
<6>[    1.822499] r8169 0000:03:00.0 enp3s0: renamed from eth0
<6>[    1.823098] hid-generic 0003:03F0:094A.0001: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[    1.823195] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.0/0003:0461:0010.0002/input/input8
<6>[    1.876870] hid-generic 0003:0461:0010.0002: input,hidraw1: USB HID v1.10 Keyboard [NOVATEK USB Keyboard] on usb-0000:00:14.0-2/input0
<6>[    1.877755] input: NOVATEK USB Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-2/1-2:1.1/0003:0461:0010.0003/input/input9
<6>[    1.932926] hid-generic 0003:0461:0010.0003: input,hidraw2: USB HID v1.10 Device [NOVATEK USB Keyboard] on usb-0000:00:14.0-2/input1
<6>[    2.116931] ata1: SATA link up 6.0 Gbps (SStatus 133 SControl 300)
<6>[    2.116949] ata5: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
<6>[    2.118032] ata1.00: ATA-8: WDC WD5000AAKX-60U6AA0, 18.01H18, max UDMA/100
<6>[    2.118035] ata1.00: 976773168 sectors, multi 16: LBA48 NCQ (depth 31/32), AA
<6>[    2.119560] ata1.00: configured for UDMA/100
<5>[    2.119732] scsi 0:0:0:0: Direct-Access    ATA      WDC WD5000AAKX-6 1H18 PQ: 0 ANSI: 5
<5>[    2.119934] sd 0:0:0:0: [sda] 976773168 512-byte logical blocks: (500 GB/465 GiB)
<5>[    2.119955] sd 0:0:0:0: Attached scsi generic sg0 type 0
<5>[    2.119976] sd 0:0:0:0: [sda] Write Protect is off
<7>[    2.119977] sd 0:0:0:0: [sda] Mode Sense: 00 3a 00 00
<5>[    2.119990] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
<6>[    2.120168] ata5.00: ATAPI: hp      DVD A  DH16AFSH, DHH6, max UDMA/133
<6>[    2.121190] ata5.00: configured for UDMA/133
<5>[    2.123519] scsi 4:0:0:0: CD-ROM            hp      DVD A  DH16AFSH  DHH6 PQ: 0 ANSI: 5
<6>[    2.131651]  sda: sda1 sda2 < sda5 >
<5>[    2.132009] sd 0:0:0:0: [sda] Attached SCSI disk
<6>[    2.144156] sr 4:0:0:0: [sr0] scsi3-mmc drive: 40x/40x writer dvd-ram cd/rw xa/form2 cdda tray
<6>[    2.144159] cdrom: Uniform CD-ROM driver Revision: 3.20
<7>[    2.144234] sr 4:0:0:0: Attached scsi CD-ROM sr0
<5>[    2.144264] sr 4:0:0:0: Attached scsi generic sg1 type 5
<6>[    2.569302] clocksource: Switched to clocksource tsc
<6>[  62.038308] usb 1-1: USB disconnect, device number 2
<6>[  63.546475] usb 1-1: new low-speed USB device number 4 using xhci_hcd
<6>[  63.678162] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  63.678164] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  63.678166] usb 1-1: Product: HP USB Optical Mouse
<6>[  63.678167] usb 1-1: Manufacturer: PixArt
<4>[  63.678304] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  63.680283] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0004/input/input10
<6>[  63.680477] hid-generic 0003:03F0:094A.0004: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  123.792223] usb 1-1: USB disconnect, device number 4
<6>[  125.300296] usb 1-1: new low-speed USB device number 5 using xhci_hcd
<6>[  125.432040] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  125.432042] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  125.432044] usb 1-1: Product: HP USB Optical Mouse
<6>[  125.432045] usb 1-1: Manufacturer: PixArt
<4>[  125.432189] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  125.433940] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0005/input/input11
<6>[  125.434002] hid-generic 0003:03F0:094A.0005: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  185.546098] usb 1-1: USB disconnect, device number 5
<6>[  187.054119] usb 1-1: new low-speed USB device number 6 using xhci_hcd
<6>[  187.185882] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  187.185884] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  187.185885] usb 1-1: Product: HP USB Optical Mouse
<6>[  187.185886] usb 1-1: Manufacturer: PixArt
<4>[  187.186025] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  187.188059] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0006/input/input12
<6>[  187.188307] hid-generic 0003:03F0:094A.0006: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  247.291968] usb 1-1: USB disconnect, device number 6
<6>[  248.799931] usb 1-1: new low-speed USB device number 7 using xhci_hcd
<6>[  248.931787] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  248.931789] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  248.931790] usb 1-1: Product: HP USB Optical Mouse
<6>[  248.931791] usb 1-1: Manufacturer: PixArt
<4>[  248.931932] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  248.934015] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0007/input/input13
<6>[  248.934187] hid-generic 0003:03F0:094A.0007: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  309.037838] usb 1-1: USB disconnect, device number 7
<6>[  310.545745] usb 1-1: new low-speed USB device number 8 using xhci_hcd
<6>[  310.677461] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  310.677462] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  310.677464] usb 1-1: Product: HP USB Optical Mouse
<6>[  310.677465] usb 1-1: Manufacturer: PixArt
<4>[  310.677601] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  310.679554] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0008/input/input14
<6>[  310.679805] hid-generic 0003:03F0:094A.0008: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  370.783709] usb 1-1: USB disconnect, device number 8
<6>[  372.291561] usb 1-1: new low-speed USB device number 9 using xhci_hcd
<6>[  372.423340] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  372.423351] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  372.423353] usb 1-1: Product: HP USB Optical Mouse
<6>[  372.423354] usb 1-1: Manufacturer: PixArt
<4>[  372.423504] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  372.425432] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.0009/input/input15
<6>[  372.425586] hid-generic 0003:03F0:094A.0009: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<5>[  427.460486] random: nonblocking pool is initialized
<6>[  432.529572] usb 1-1: USB disconnect, device number 9
<6>[  434.037375] usb 1-1: new low-speed USB device number 10 using xhci_hcd
<6>[  434.169057] usb 1-1: New USB device found, idVendor=03f0, idProduct=094a
<6>[  434.169059] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
<6>[  434.169061] usb 1-1: Product: HP USB Optical Mouse
<6>[  434.169062] usb 1-1: Manufacturer: PixArt
<4>[  434.169155] usb 1-1: ep 0x81 - rounding interval to 64 microframes, ep desc says 80 microframes
<6>[  434.170858] input: PixArt HP USB Optical Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-1/1-1:1.0/0003:03F0:094A.000A/input/input16
<6>[  434.170920] hid-generic 0003:03F0:094A.000A: input,hidraw0: USB HID v1.11 Mouse [PixArt HP USB Optical Mouse] on usb-0000:00:14.0-1/input0
<6>[  454.417894] NET: Registered protocol family 38
<6>[  472.630604] EXT4-fs (dm-1): mounted filesystem with ordered data mode. Opts: (null)
<28>[  473.978841] systemd[1]: Failed to insert module 'kdbus': Function not implemented
<30>[  474.139970] systemd[1]: systemd 225 running in system mode. (+PAM +AUDIT +SELINUX +IMA +APPARMOR +SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ -LZ4 +SECCOMP +BLKID -ELFUTILS +KMOD -IDN)
<30>[  474.140056] systemd[1]: Detected architecture x86-64.
<30>[  474.153904] systemd[1]: Set hostname to <admin-H>.
<30>[  474.546056] systemd[1]: Created slice Root Slice.
<30>[  474.546121] systemd[1]: Listening on udev Control Socket.
<30>[  474.546142] systemd[1]: Listening on Journal Socket (/dev/log).
<30>[  474.546156] systemd[1]: Listening on fsck to fsckd communication Socke
t.
<30>[  474.546211] systemd[1]: Created slice User and Session Slice.
<30>[  474.546228] systemd[1]: Listening on udev Kernel Socket.
<30>[  474.546275] systemd[1]: Created slice System Slice.
<30>[  474.546326] systemd[1]: Created slice system-getty.slice.
<30>[  474.546642] systemd[1]: Starting Increase datagram queue length...
<30>[  474.546670] systemd[1]: Reached target Slices.
<30>[  474.546701] systemd[1]: Listening on /dev/initctl Compatibility Named Pipe.
<30>[  474.546739] systemd[1]: Started Forward Password Requests to Wall Directory Watch.
<30>[  474.546751] systemd[1]: Reached target Remote File Systems (Pre).
<30>[  474.546781] systemd[1]: Listening on LVM2 poll daemon socket.
<30>[  474.546887] systemd[1]: Set up automount Arbitrary Executable File Formats File System Automount Point.
<30>[  474.546914] systemd[1]: Listening on Device-mapper event daemon FIFOs.
<30>[  474.546930] systemd[1]: Reached target User and Group Name Lookups.
<30>[  474.547012] systemd[1]: Created slice system-systemd\x2dfsck.slice.
<30>[  474.547040] systemd[1]: Listening on Journal Socket.
<30>[  474.547322] systemd[1]: Mounting POSIX Message Queue File System...
<30>[  474.684569] systemd[1]: Starting Load Kernel Modules...
<30>[  474.684940] systemd[1]: Started Read required files in advance.
<30>[  474.685518] systemd[1]: Mounting Huge Pages File System...
<30>[  474.685883] systemd[1]: Starting Create list of required static device nodes for the current kernel...
<30>[  474.686334] systemd[1]: Starting Uncomplicated firewall...
<30>[  474.686746] systemd[1]: Started Braille Device Support.
<30>[  474.687812] systemd[1]: Starting udev Coldplug all Devices...
<30>[  474.688318] systemd[1]: Mounting Debug File System...
<30>[  474.688612] systemd[1]: Starting Setup Virtual Console...
<30>[  474.688666] systemd[1]: Listening on LVM2 metadata daemon socket.
<30>[  474.689083] systemd[1]: Starting Monitoring of LVM2 mirrors, snapshots etc. using dmeventd or progress polling...
<30>[  474.689140] systemd[1]: Listening on Journal Audit Socket.
<30>[  474.997305] systemd[1]: Created slice system-systemd\x2dcryptsetup.slice.
<30>[  474.997996] systemd[1]: Started Create list of required static device nodes for the current kernel.
<30>[  474.998430] systemd[1]: Started Setup Virtual Console.
<30>[  475.001314] systemd[1]: Starting Create Static Device Nodes in /dev...
<30>[  475.026807] systemd[1]: Started udev Coldplug all Devices.
<30>[  475.120785] systemd[1]: Mounted Debug File System.
<30>[  475.120837] systemd[1]: Mounted POSIX Message Queue File System.
<30>[  475.120867] systemd[1]: Mounted Huge Pages File System.
<30>[  475.121023] systemd[1]: Started Increase datagram queue length.
<30>[  475.124340] systemd[1]: Listening on Syslog Socket.
<30>[  475.124705] systemd[1]: Starting Journal Service...
<6>[  475.233032] lp: driver loaded but no devices found
<6>[  475.247425] ppdev: user-space parallel port driver
<30>[  475.292966] systemd[1]: Started Load Kernel Modules.
<30>[  475.293440] systemd[1]: Starting Apply Kernel Variables...
<30>[  475.293791] systemd[1]: Mounting FUSE Control File System...
<30>[  475.296087] systemd[1]: Mounted FUSE Control File System.
<6>[  475.352486] ip_tables: (C) 2000-2006 Netfilter Core Team
<6>[  475.393607] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
<30>[  475.495803] systemd[1]: Started Journal Service.
<6>[  475.508367] ip6_tables: (C) 2000-2006 Netfilter Core Team
<6>[  478.508295] EXT4-fs (dm-1): re-mounted. Opts: errors=remount-ro
<6>[  478.758644] shpchp: Standard Hot Plug PCI Controller Driver version: 0.4
<46>[  478.843932] systemd-journald[437]: Received request to flush runtime journal from PID 1
<4>[  479.260292] kvm: disabled by bios
<4>[  479.302151] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
<4>[  479.302155] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302161] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302185] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
<4>[  479.302187] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302190] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302211] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
<4>[  479.302212] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302215] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<6>[  479.302254] input: HP WMI hotkeys as /devices/virtual/input/input17
<4>[  479.302740] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
<4>[  479.302743] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302747] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Node ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302769] ACPI Error: Field [D128] at 1152 exceeds Buffer [NULL] size 160 (bits) (20150619/dsopcode-236)
<4>[  479.302771] ACPI Error: Method parse/execution failed [\HWMC] (Node ffff88011b0befa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<4>[  479.302774] ACPI Error: Method parse/execution failed [\_SB_.WMID.WMAA] (Nod
e ffff88011b0c1fa0), AE_AML_BUFFER_LIMIT (20150619/psparse-536)
<6>[  480.200523] intel_rapl: Found RAPL domain package
<6>[  480.200526] intel_rapl: Found RAPL domain core
<6>[  480.200527] intel_rapl: Found RAPL domain uncore
<6>[  480.200528] intel_rapl: Found RAPL domain dram
<6>[  487.850441] Adding 4115964k swap on /dev/mapper/cryptswap1.  Priority:-1 extents:1 across:4115964k FS
<6>[  492.591832] EXT4-fs (sda1): mounting ext2 file system using the ext4 subsystem
<6>[  492.661255] EXT4-fs (sda1): mounted filesystem without journal. Opts: (null)
<5>[  497.478978] audit: type=1400 audit(1458033907.867:2): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/lightdm/lightdm-guest-session" pid=735 comm="apparmor_parser"
<5>[  497.478985] audit: type=1400 audit(1458033907.867:3): apparmor="STATUS" operation="profile_load" profile="unconfined" name="chromium" pid=735 comm="apparmor_parser"
<5>[  497.525022] audit: type=1400 audit(1458033907.915:4): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/sbin/dhclient" pid=735 comm="apparmor_parser"
<5>[  497.525028] audit: type=1400 audit(1458033907.915:5): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=735 comm="apparmor_parser"
<5>[  497.525031] audit: type=1400 audit(1458033907.915:6): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-helper" pid=735 comm="apparmor_parser"
<5>[  497.525034] audit: type=1400 audit(1458033907.915:7): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=735 comm="apparmor_parser"
<5>[  497.556986] audit: type=1400 audit(1458033907.947:8): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince" pid=735 comm="apparmor_parser"
<5>[  497.556994] audit: type=1400 audit(1458033907.947:9): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=735 comm="apparmor_parser"
<5>[  497.556998] audit: type=1400 audit(1458033907.947:10): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/evince-previewer" pid=735 comm="apparmor_parser"
<5>[  497.557002] audit: type=1400 audit(1458033907.947:11): apparmor="STATUS" operation="profile_load" profile="unconfined" name="sanitized_helper" pid=735 comm="apparmor_parser"
<4>[  498.136316] cgroup: new mount options do not match the existing superblock, will be ignored
<6>[  502.240545] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
<6>[  502.447098] r8169 0000:03:00.0 enp3s0: link down
<6>[  502.447126] IPv6: ADDRCONF(NETDEV_UP): enp3s0: link is not ready
<6>[  932.201331] r8169 0000:03:00.0 enp3s0: link up
<6>[  932.201339] IPv6: ADDRCONF(NETDEV_CHANGE): enp3s0: link becomes ready
<4>[  932.692793] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=597 DF PROTO=2
<4>[ 1042.808500] ICMPv6: process `grep' is using deprecated sysctl (syscall) net.ipv6.neigh.default.base_reachable_time - use net.ipv6.neigh.default.base_reachable_time_ms instead
<4>[ 1042.926003] nr_pdflush_threads exported in /proc is scheduled for removal
<4>[ 1057.795539] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=2518 DF PROTO=2
<4>[ 1182.898205] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=9116 DF PROTO=2
<4>[ 1308.000475] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=19778 DF PROTO=2
<4>[ 1433.102744] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=30173 DF PROTO=2
<4>[ 1558.205356] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=41896 DF PROTO=2
<4>[ 1683.307272] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=52400 DF PROTO=2
<4>[ 1808.409133] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=53754 DF PROTO=2
<4>[ 1933.511182] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=55851 DF PROTO=2
<4>[ 2058.613349] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=64376 DF PROTO=2
<4>[ 2183.715453] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=65526 DF PROTO=2
<4>[ 2308.817432] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=3377 DF PROTO=2
<4>[ 2433.919308] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=6864 DF PROTO=2
<4>[ 2559.021460] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=18349 DF PROTO=2
<4>[ 2684.124178] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=20562 DF PROTO=2
<4>[ 2809.226337] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=28237 DF PROTO=2
<4>[ 2934.328174] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=33046 DF PROTO=2
<4>[ 3059.430483] [UFW BLOCK] IN=enp3s0 OUT= MAC=01:00:5e:00:00:01:c8:0e:14:d8:47:41:08:00 SRC=192.168.178.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0xC0 TTL=1 ID=41547 DF PROTO=2


Fragerin 15.03.2016 12:28

Warum denkst du, dass diese Sachen unnormal sind? Hast du da irgendwelche Quellen dazu?

Dass die Netzwerk-Interfaces nicht mehr eth0 und wlan0 heißen, sondern eher kryptische Namen haben, ist z.B. laut diesem Link ganz normal:
https://www.freedesktop.org/wiki/Sof...nterfaceNames/

cosinus 15.03.2016 16:13

Zitat:

Zitat von Fragerin (Beitrag 1570506)
Warum denkst du, dass diese Sachen unnormal sind? Hast du da irgendwelche Quellen dazu?

Weil der Typ keine Ahnung von Logfiles und Betriebssystemen hat, aber in allem was er nicht kennt, einen Virus sieht. Ich hab ihn in seinem anderen Thread im Diskussionsbereich schon mehrfach aufgefordert endlich mal handfeste Beweise für ne Infektion zu liefern, meine Fragen zu beantworten, aber stattdessen kommen irgendwelche ellenlangen Ausgaben die völlig irrelevant sind. :kaffee:

Not sure if stupid or trolling... :blabla:

KernelpanicX 15.03.2016 23:17

Der junge Padawan scheint wirklich etwas verwirrt zu sein. Vielleicht muß der Kopf nur einfach mal wieder richtig frei gemacht werden. Für mich reicht dann so etwas:

Taylors Fine White Port oder
Delaforce Special White Port
:daumenhoc:
:alc:

Fragerin 16.03.2016 08:15

Aber man kann doch als Normalmensch mit kaum einem Eintrag aus dmesg wirklich was anfangen. Der TO hat aber nicht das halbe Log unterstrichen, sondern einige ausgewählte Einträge. Da muss er doch irgendwelche Kriterien dafür haben.
Hmmm... evtl. Vergleich mit einem älteren Ubuntu, auf dem systemd noch nicht am Start war?

cosinus 16.03.2016 09:12

Ähm ja, und? :wtf:
Die allermeisten Einträge zeigt auch mein dmesg. Da wird halt jeder sch... drin protokolliert:

Code:

cosinus@ubuntu:~$ dmesg |grep Calg
[    0.000000] Calgary: detecting Calgary via BIOS EBDA area
[    0.000000] Calgary: Unable to locate Rio Grande table in EBDA - bailing!
cosinus@ubuntu:~$ dmesg |grep parav
[    0.000000] Booting paravirtualized kernel on bare hardware
cosinus@ubuntu:~$ dmesg |grep Fak
[    0.000000] Faking a node at [mem 0x0000000000000000-0x000000041effffff]
cosinus@ubuntu:~$ dmesg |grep checksum
[    0.000000] ACPI: Early table checksum verification disabled
[    0.865195] r8169 0000:03:00.0 eth0: jumbo features [frames: 9200 bytes, tx checksumming: ko]
cosinus@ubuntu:~$ dmesg |grep -i "acpi error"
[    1.203714] ACPI Error: [DSSP] Namespace lookup failure, AE_NOT_FOUND (20150619/psargs-359)
[    1.204096] ACPI Error: Method parse/execution failed [\_SB_.PCI0.SAT0.SPT4._GTF] (Node ffff88040e0d1460), AE_NOT_FOUND (20150619/psparse-536)
[    1.213999] ACPI Error: [DSSP] Namespace lookup failure, AE_NOT_FOUND (20150619/psargs-359)
[    1.214369] ACPI Error: Method parse/execution failed [\_SB_.PCI0.SAT0.SPT4._GTF] (Node ffff88040e0d1460), AE_NOT_FOUND (20150619/psparse-536)

Hm, hab ich jetzt auch ein rootkit drin und wusste davon die ganze Zeit bisher nix davon? :dummguck: iceweasel, Hilfe! :D

Fragerin 16.03.2016 09:27

Vielleicht ist dein "Bootkit" auch systemd und andere neuere Entwicklungen bei Linux :-)

Ich meine ja bloß, wenn er uns erklärt, wie er darauf kommt, hätten wir eine Basis, ihm zu erklären, was da wirklich los ist.

Dante12 16.03.2016 11:36

Für mich sieht das so aus als ob alles wild durcheinander zusammengesucht wurde :D

Um mal das Log von Cosinus auf die schnelle zu analysieren:

Zitat:

Calgary: detecting Calgary via BIOS EBDA area
Das Modul wird geladen obwohl auf den Rechner keine entsprechende Hardware verbaut ist. Daher die Fehlermeldung. Hier auch der Bug Report vor einiger Zeit.

Zitat:

Booting paravirtualized kernel on bare hardware
Das ist ein Kernel der für die Virtualisierung augelegt ist jedoch auf echter Hardware läuft.

Zudem ist das Netzwerk von @cosinus auf Jumbo-Frames ausgelegt.

Zitat:

ACPI Error: Method parse/execution failed
Für gewöhnlich hat dieser Fehler keine direkte auswirkung könnte aber mit dem Power Management Probleme bekommen. Sofern da nichts beim Arbeiten auffällig ist (Abstürze, Hänger etc.) kann das ignoriert werden.
Andernfalls sollte man im Bios mal nach ACPI=Legacy schauen.

Also alles Rootkits die für das System entwickelt wurden :D

cosinus 16.03.2016 23:29

Das richtige fiese rootkit hast du übersehen, sieht man auf Mac OS X nicht, weil mit Linux Geheimtinte hier gepostet :rofl:

Code:

cosinus@ubuntu:~$ dmesg |grep Fak
[    0.000000] Faking a node at [mem 0x0000000000000000-0x000000041effffff]


dennissteins 17.03.2016 01:54

Will euch nicht weiter nerven mit meinen Einbildungen und meiner Unwissenheit, aber drei Logs habe ich noch....Nach /Während Clientenzugriff:

Code:


ruut@ruut-HP-280-G1-MT:~$ sudo chkrootkit
[sudo] password for ruut:
ROOTDIR is `/'
Checking `amd'...                                          not found
Checking `basename'...                                      not infected
Checking `biff'...                                          not found
Checking `chfn'...                                          not infected
Checking `chsh'...                                          not infected
Checking `cron'...                                          not infected
Checking `crontab'...                                      not infected
Checking `date'...                                          not infected
Checking `du'...                                            not infected
Checking `dirname'...                                      not infected
Checking `echo'...                                          not infected
Checking `egrep'...                                        not infected
Checking `env'...                                          not infected
Checking `find'...                                          not infected
Checking `fingerd'...                                      not found
Checking `gpm'...                                          not found
Checking `grep'...                                          not infected
Checking `hdparm'...                                        not infected
Checking `su'...                                            not infected
Checking `ifconfig'...                                      not infected
Checking `inetd'...                                        not infected
Checking `inetdconf'...                                    not infected
Checking `identd'...                                        not found
Checking `init'...                                          not infected
Checking `killall'...                                      not infected
Checking `ldsopreload'...                                  not infected
Checking `login'...                                        not infected
Checking `ls'...                                            not infected
Checking `lsof'...                                          not infected
Checking `mail'...                                          not infected
Checking `mingetty'...                                      not found
Checking `netstat'...                                      not infected
Checking `named'...                                        not found
Checking `passwd'...                                        not infected
Checking `pidof'...                                        not infected
Checking `pop2'...                                          not found
Checking `pop3'...                                          not found
Checking `ps'...                                            not infected
Checking `pstree'...                                        not infected
Checking `rpcinfo'...                                      not found
Checking `rlogind'...                                      not found
Checking `rshd'...                                          not found
Checking `slogin'...                                        not infected
Checking `sendmail'...                                      not infected
Checking `sshd'...                                          not found
Checking `syslogd'...                                      not tested
Checking `tar'...                                          not infected
Checking `tcpd'...                                          not infected
Checking `tcpdump'...                                      not infected
Checking `top'...                                          not infected
Checking `telnetd'...                                      not found
Checking `timed'...                                        not found
Checking `traceroute'...                                    not found
Checking `vdir'...                                          not infected
Checking `w'...                                            not infected
Checking `write'...                                        not infected
Checking `aliens'...                                        no suspect files
Searching for sniffer's logs, it may take a while...        nothing found
Searching for rootkit HiDrootkit's default files...        nothing found
Searching for rootkit t0rn's default files...              nothing found
Searching for t0rn's v8 defaults...                        nothing found
Searching for rootkit Lion's default files...              nothing found
Searching for rootkit RSHA's default files...              nothing found
Searching for rootkit RH-Sharpe's default files...          nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found: 
/usr/lib/debug/.build-id /usr/lib/python2.7/dist-packages/PyQt4/uic/widget-plugins/.noinit /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_anon/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_anon/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_time/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_time/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/basic/file/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/basic/file/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/basic/authz_owner/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/basic/authz_owner/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_wrongrelm/.htpasswd /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/digest_wrongrelm/.htaccess /usr/lib/python3/dist-packages/fail2ban/tests/files/config/apache-auth/noentry/.htaccess /lib/modules/4.2.0-34-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id
/usr/lib/debug/.build-id /lib/modules/4.2.0-34-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id
Searching for LPD Worm files and dirs...                    nothing found
Searching for Ramen Worm files and dirs...                  nothing found
Searching for Maniac files and dirs...                      nothing found
Searching for RK17 files and dirs...                        nothing found
Searching for Ducoci rootkit...                            nothing found
Searching for Adore Worm...                                nothing found
Searching for ShitC Worm...                                nothing found
Searching for Omega Worm...                                nothing found
Searching for Sadmind/IIS Worm...                          nothing found
Searching for MonKit...                                    nothing found
Searching for Showtee...                                    nothing found
Searching for OpticKit...                                  nothing found
Searching for T.R.K...                                      nothing found
Searching for Mithra...                                    nothing found
Searching for LOC rootkit...                                nothing found
Searching for Romanian rootkit...                          nothing found
Searching for Suckit rootkit...                            nothing found
Searching for Volc rootkit...                              nothing found
Searching for Gold2 rootkit...                              nothing found
Searching for TC2 Worm default files and dirs...            nothing found
Searching for Anonoying rootkit default files and dirs...  nothing found
Searching for ZK rootkit default files and dirs...          nothing found
Searching for ShKit rootkit default files and dirs...      nothing found
Searching for AjaKit rootkit default files and dirs...      nothing found
Searching for zaRwT rootkit default files and dirs...      nothing found
Searching for Madalin rootkit default files...              nothing found
Searching for Fu rootkit default files...                  nothing found
Searching for ESRK rootkit default files...                nothing found
Searching for rootedoor...                                  nothing found
Searching for ENYELKM rootkit default files...              nothing found
Searching for common ssh-scanners default files...          nothing found
Searching for Linux/Ebury - Operation Windigo ssh...        Possible Linux/Ebury - Operation Windigo installetd
Searching for 64-bit Linux Rootkit ...                      nothing found
Searching for 64-bit Linux Rootkit modules...              nothing found
Searching for suspect PHP files...                          nothing found
Searching for anomalies in shell history files...          nothing found
Checking `asp'...                                          not infected
Checking `bindshell'...                                    not infected
Checking `lkm'...                                          chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'...                                      not found
Checking `sniffer'...                                      lo: not promisc and no packet sniffer sockets
enp3s0: PACKET SNIFFER(/sbin/dhclient[1007], /usr/bin/ettercap[4481])
Checking `w55808'...                                        not infected
Checking `wted'...                                          chkwtmp: nothing deleted
Checking `scalper'...                                      not infected
Checking `slapper'...                                      not infected
Checking `z2'...                                            user ruut deleted or never logged from lastlog!
user root deleted or never logged from lastlog!
Checking `chkutmp'...                                        The tty of the following user process(es) were not found
 in /var/run/utmp !
! RUID          PID TTY    CMD
! root        1291 tty7  /usr/bin/X -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
chkutmp: nothing deleted
Checking `OSX_RSPLUG'...                                    not infected
ruut@ruut-HP-280-G1-MT:~$

Code:

[00:40:56] Running Rootkit Hunter version 1.4.2 on ruut-HP-280-G1-MT
[00:40:56]
[00:40:56] Info: Start date is Do 17. Mär 00:40:56 CET 2016
[00:40:56]
[00:40:56] Checking configuration file and command-line options...
[00:40:56] Info: Detected operating system is 'Linux'
[00:40:56] Info: Found O/S name: Ubuntu 15.10
[00:40:56] Info: Command line is /usr/bin/rkhunter -c
[00:40:56] Info: Environment shell is /bin/bash; rkhunter is using dash
[00:40:56] Info: Using configuration file '/etc/rkhunter.conf'
[00:40:56] Info: Installation directory is '/usr'
[00:40:56] Info: Using language 'en'
[00:40:56] Info: Using '/var/lib/rkhunter/db' as the database directory
[00:40:56] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[00:40:56] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[00:40:56] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[00:40:56] Info: No mail-on-warning address configured
[00:40:56] Info: X will be automatically detected
[00:40:56] Info: Using second color set
[00:40:56] Info: Found the 'basename' command: /usr/bin/basename
[00:40:57] Info: Found the 'diff' command: /usr/bin/diff
[00:40:57] Info: Found the 'dirname' command: /usr/bin/dirname
[00:40:57] Info: Found the 'file' command: /usr/bin/file
[00:40:57] Info: Found the 'find' command: /usr/bin/find
[00:40:57] Info: Found the 'ifconfig' command: /sbin/ifconfig
[00:40:57] Info: Found the 'ip' command: /sbin/ip
[00:40:57] Info: Found the 'ipcs' command: /usr/bin/ipcs
[00:40:57] Info: Found the 'ldd' command: /usr/bin/ldd
[00:40:57] Info: Found the 'lsattr' command: /usr/bin/lsattr
[00:40:57] Info: Found the 'lsmod' command: /sbin/lsmod
[00:40:57] Info: Found the 'lsof' command: /usr/bin/lsof
[00:40:57] Info: Found the 'mktemp' command: /bin/mktemp
[00:40:57] Info: Found the 'netstat' command: /bin/netstat
[00:40:57] Info: Found the 'perl' command: /usr/bin/perl
[00:40:57] Info: Found the 'pgrep' command: /usr/bin/pgrep
[00:40:57] Info: Found the 'ps' command: /bin/ps
[00:40:57] Info: Found the 'pwd' command: /bin/pwd
[00:40:57] Info: Found the 'readlink' command: /bin/readlink
[00:40:57] Info: Found the 'stat' command: /usr/bin/stat
[00:40:57] Info: Found the 'strings' command: /usr/bin/strings
[00:40:57] Info: System is not using prelinking
[00:40:57] Info: Using the '/usr/bin/sha256sum' command for the file hash checks
[00:40:57] Info: Stored hash values used hash function '/usr/bin/sha256sum'
[00:40:57] Info: Stored hash values did not use a package manager
[00:40:57] Info: The hash function field index is set to 1
[00:40:57] Info: No package manager specified: using hash function '/usr/bin/sha256sum'
[00:40:57] Info: Previous file attributes were stored
[00:40:57] Info: Enabled tests are: all
[00:40:57] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[00:40:58] Info: Found ksym file '/proc/kallsyms'
[00:40:58] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[00:40:58] Info: Using 'date' to process epoch second times
[00:40:58]
[00:40:58] Checking if the O/S has changed since last time...
[00:40:58] Info: Nothing seems to have changed.
[00:40:58] Info: Locking is not being used
[00:40:58]
[00:40:58] Starting system checks...
[00:40:58]
[00:40:58] Info: Starting test name 'system_commands'
[00:40:58] Checking system commands...
[00:40:58]
[00:40:58] Info: Starting test name 'strings'
[00:40:58] Performing 'strings' command checks
[00:40:58]  Scanning for string /usr/sbin/ntpsx            [ OK ]
[00:40:58]  Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[00:40:58]  Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[00:40:58]  Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[00:40:58]  Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[00:40:59]  Scanning for string /usr/include/.../proc.h    [ OK ]
[00:40:59]  Scanning for string /usr/include/.../.bash_history [ OK ]
[00:40:59]  Scanning for string /usr/include/.../bkit-get  [ OK ]
[00:40:59]  Scanning for string /usr/include/.../bkit-dl    [ OK ]
[00:40:59]  Scanning for string /usr/include/.../bkit-screen [ OK ]
[00:40:59]  Scanning for string /usr/include/.../bkit-sleep [ OK ]
[00:40:59]  Scanning for string /usr/lib/.../bkit-adore.o  [ OK ]
[00:40:59]  Scanning for string /usr/lib/.../ls            [ OK ]
[00:40:59]  Scanning for string /usr/lib/.../netstat        [ OK ]
[00:40:59]  Scanning for string /usr/lib/.../lsof          [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[00:41:00]  Scanning for string /usr/lib/.../psr            [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../find          [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../pstree        [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../slocate        [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../du            [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../top            [ OK ]
[00:41:01]  Scanning for string /usr/sbin/...              [ OK ]
[00:41:01]  Scanning for string /usr/include/...            [ OK ]
[00:41:01]  Scanning for string /usr/include/.../.tmp      [ OK ]
[00:41:01]  Scanning for string /usr/lib/...                [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../.ssh          [ OK ]
[00:41:01]  Scanning for string /usr/lib/.../bkit-ssh      [ OK ]
[00:41:02]  Scanning for string /usr/lib/.bkit-            [ OK ]
[00:41:02]  Scanning for string /tmp/.bkp                  [ OK ]
[00:41:02]  Scanning for string /tmp/.cinik                [ OK ]
[00:41:02]  Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[00:41:02]  Scanning for string /lib/.sso                  [ OK ]
[00:41:02]  Scanning for string /lib/.so                    [ OK ]
[00:41:02]  Scanning for string /var/run/...dica/clean      [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/dxr        [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/read      [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/write      [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/lf        [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/xl        [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/xdr        [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/psg        [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/secure    [ OK ]
[00:41:03]  Scanning for string /var/run/...dica/rdx        [ OK ]
[00:41:04]  Scanning for string /var/run/...dica/va        [ OK ]
[00:41:04]  Scanning for string /var/run/...dica/cl.sh      [ OK ]
[00:41:04]  Scanning for string /var/run/...dica/last.log  [ OK ]
[00:41:04]  Scanning for string /usr/bin/.etc              [ OK ]
[00:41:04]  Scanning for string /etc/sshd_config            [ OK ]
[00:41:04]  Scanning for string /etc/ssh_host_key          [ OK ]
[00:41:04]  Scanning for string /etc/ssh_random_seed        [ OK ]
[00:41:04]  Scanning for string /dev/ptyp                  [ OK ]
[00:41:05]  Scanning for string /dev/ptyq                  [ OK ]
[00:41:05]  Scanning for string /dev/ptyr                  [ OK ]
[00:41:05]  Scanning for string /dev/ptys                  [ OK ]
[00:41:05]  Scanning for string /dev/ptyt                  [ OK ]
[00:41:05]  Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[00:41:06]  Scanning for string /dev/fd/.88/fresht          [ OK ]
[00:41:06]  Scanning for string /dev/fd/.88/zxsniff        [ OK ]
[00:41:06]  Scanning for string /dev/fd/.88/zxsniff.log    [ OK ]
[00:41:06]  Scanning for string /dev/fd/.99/.ttyf00        [ OK ]
[00:41:06]  Scanning for string /dev/fd/.99/.ttyp00        [ OK ]
[00:41:06]  Scanning for string /dev/fd/.99/.ttyq00        [ OK ]
[00:41:06]  Scanning for string /dev/fd/.99/.ttys00        [ OK ]
[00:41:06]  Scanning for string /dev/fd/.99/.pwsx00        [ OK ]
[00:41:06]  Scanning for string /etc/.acid                  [ OK ]
[00:41:06]  Scanning for string /usr/lib/.fx/sched_host.2  [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/random_d.2    [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/TOHIDE        [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/cons.saver    [ OK ]
[00:41:07]  Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[00:41:08]  Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[00:41:08]  Scanning for string /bin/sysback                [ OK ]
[00:41:08]  Scanning for string /usr/local/bin/sysback      [ OK ]
[00:41:08]  Scanning for string /usr/lib/.tbd              [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/t0rns    [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/t0rnp    [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/ssh.tgz  [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/top      [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[00:41:08]  Scanning for string /dev/.lib/lib/lib/login    [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/1i0n.sh  [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/mjy      [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/tfn      [ OK ]
[00:41:09]  Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[00:41:10]  Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[00:41:10]  Scanning for string /usr/info/.torn/sh*        [ OK ]
[00:41:10]  Scanning for string /usr/src/.puta/.1addr      [ OK ]
[00:41:10]  Scanning for string /usr/src/.puta/.1file      [ OK ]
[00:41:10]  Scanning for string /usr/src/.puta/.1proc      [ OK ]
[00:41:10]  Scanning for string /usr/src/.puta/.1logz      [ OK ]
[00:41:11]  Scanning for string /usr/info/.t0rn            [ OK ]
[00:41:11]  Scanning for string /dev/.lib                  [ OK ]
[00:41:11]  Scanning for string /dev/.lib/lib              [ OK ]
[00:41:11]  Scanning for string /dev/.lib/lib/lib          [ OK ]
[00:41:11]  Scanning for string /dev/.lib/lib/lib/dev      [ OK ]
[00:41:11]  Scanning for string /dev/.lib/lib/scan          [ OK ]
[00:41:11]  Scanning for string /usr/src/.puta              [ OK ]
[00:41:11]  Scanning for string /usr/man/man1/man1          [ OK ]
[00:41:12]  Scanning for string /usr/man/man1/man1/lib      [ OK ]
[00:41:12]  Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[00:41:12]  Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[00:41:12]
[00:41:12] Info: Starting test name 'shared_libs'
[00:41:12] Performing 'shared libraries' checks
[00:41:12]  Checking for preloading variables              [ None found ]
[00:41:12]  Checking for preloaded libraries                [ None found ]
[00:41:12]
[00:41:12] Info: Starting test name 'shared_libs_path'
[00:41:12]  Checking LD_LIBRARY_PATH variable              [ Not found ]
[00:41:13]
[00:41:13] Info: Starting test name 'properties'
[00:41:13] Performing file properties checks
[00:41:13]  Checking for prerequisites                      [ OK ]
[00:41:20]  /usr/sbin/adduser                              [ OK ]
[00:41:20] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[00:41:20]  /usr/sbin/chroot                                [ OK ]
[00:41:20]  /usr/sbin/cron                                  [ OK ]
[00:41:21]  /usr/sbin/groupadd                              [ OK ]
[00:41:21]  /usr/sbin/groupdel                              [ OK ]
[00:41:22]  /usr/sbin/groupmod                              [ OK ]
[00:41:22]  /usr/sbin/grpck                                [ OK ]
[00:41:22]  /usr/sbin/inetd                                [ OK ]
[00:41:23]  /usr/sbin/nologin                              [ OK ]
[00:41:24]  /usr/sbin/pwck                                  [ OK ]
[00:41:24]  /usr/sbin/rsyslogd                              [ OK ]
[00:41:25]  /usr/sbin/tcpd                                  [ OK ]
[00:41:25]  /usr/sbin/useradd                              [ OK ]
[00:41:25]  /usr/sbin/userdel                              [ OK ]
[00:41:26]  /usr/sbin/usermod                              [ OK ]
[00:41:26]  /usr/sbin/vipw                                  [ OK ]
[00:41:26]  /usr/sbin/unhide-linux                          [ OK ]
[00:41:27]  /usr/sbin/unhide-posix                          [ OK ]
[00:41:27]  /usr/sbin/unhide-tcp                            [ OK ]
[00:41:28]  /usr/bin/awk                                    [ OK ]
[00:41:28]  /usr/bin/basename                              [ OK ]
[00:41:28]  /usr/bin/chattr                                [ OK ]
[00:41:28]  /usr/bin/curl                                  [ Warning ]
[00:41:28] Warning: The file properties have changed:
[00:41:28]          File: /usr/bin/curl
[00:41:28]          Current hash: be7fc9358c59203365c697aa690c199e3b82a4f434f0fc17645adef2943a3999
[00:41:28]          Stored hash : fdac692288d2bbecdad5ceb047a661a9991dd04c4788e788443ffac2fe0f9c96
[00:41:28]          Current inode: 12719688    Stored inode: 12714172
[00:41:28]          Current file modification time: 1453828450 (26-Jan-2016 18:14:10)
[00:41:28]          Stored file modification time : 1439252085 (11-Aug-2015 02:14:45)
[00:41:28]  /usr/bin/cut                                    [ OK ]
[00:41:29]  /usr/bin/diff                                  [ OK ]
[00:41:29]  /usr/bin/dirname                                [ OK ]
[00:41:29]  /usr/bin/dpkg                                  [ Warning ]
[00:41:29] Warning: The file properties have changed:
[00:41:29]          File: /usr/bin/dpkg
[00:41:29]          Current hash: 75869329a6e4836540f6668faa742b7924d0dbabe124251184e538e3b360fffa
[00:41:29]          Stored hash : a9d36f0882382ebee82e3ba9aa2c155e6e306ce086987d60c47f40ee302c6eb2
[00:41:29]          Current inode: 12714064    Stored inode: 12714222
[00:41:29]          Current file modification time: 1448544353 (26-Nov-2015 14:25:53)
[00:41:29]          Stored file modification time : 1445122210 (18-Okt-2015 00:50:10)
[00:41:29]  /usr/bin/dpkg-query                            [ Warning ]
[00:41:29] Warning: The file properties have changed:
[00:41:30]          File: /usr/bin/dpkg-query
[00:41:30]          Current hash: 4b52d7f69c86b7ef392e6207edfa44f11fed9b3487114ecaa7dedb8255cf31cd
[00:41:30]          Stored hash : bf117ff011b6cf1eb2469611f61b8cdb7fae4a0d61c7538cf080dc7ac3048934
[00:41:30]          Current inode: 12714165    Stored inode: 12714238
[00:41:30]          Current file modification time: 1448544353 (26-Nov-2015 14:25:53)
[00:41:30]          Stored file modification time : 1445122210 (18-Okt-2015 00:50:10)
[00:41:30]  /usr/bin/du                                    [ OK ]
[00:41:30]  /usr/bin/env                                    [ OK ]
[00:41:30]  /usr/bin/file                                  [ OK ]
[00:41:30]  /usr/bin/find                                  [ OK ]
[00:41:31]  /usr/bin/GET                                    [ OK ]
[00:41:31]  /usr/bin/groups                                [ OK ]
[00:41:31]  /usr/bin/head                                  [ OK ]
[00:41:31]  /usr/bin/id                                    [ OK ]
[00:41:31]  /usr/bin/killall                                [ OK ]
[00:41:32]  /usr/bin/last                                  [ OK ]
[00:41:32]  /usr/bin/lastlog                                [ OK ]
[00:41:32]  /usr/bin/ldd                                    [ Warning ]
[00:41:32] Warning: The file properties have changed:
[00:41:32]          File: /usr/bin/ldd
[00:41:32]          Current hash: 7b253d20dcc8c0d57e1e15bdae100f57e1a3a80e6e5c7b5940f695a2dba5c622
[00:41:32]          Stored hash : 1700e8168588e8036760cb1cb039f955d569bec1d63d579542d6f0ecfa08ac99
[00:41:32]          Current inode: 12716834    Stored inode: 12714663
[00:41:32]          Current size: 5422    Stored size: 5420
[00:41:32]          Current file modification time: 1455650074 (16-Feb-2016 20:14:34)
[00:41:32]          Stored file modification time : 1427353185 (26-Mär-2015 07:59:45)
[00:41:32] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[00:41:32]  /usr/bin/less                                  [ OK ]
[00:41:33]  /usr/bin/locate                                [ OK ]
[00:41:33]  /usr/bin/logger                                [ OK ]
[00:41:33]  /usr/bin/lsattr                                [ OK ]
[00:41:33]  /usr/bin/lsof                                  [ OK ]
[00:41:34]  /usr/bin/mail                                  [ OK ]
[00:41:34]  /usr/bin/md5sum                                [ OK ]
[00:41:34]  /usr/bin/mlocate                                [ OK ]
[00:41:35]  /usr/bin/newgrp                                [ OK ]
[00:41:35]  /usr/bin/passwd                                [ OK ]
[00:41:35]  /usr/bin/perl                                  [ Warning ]
[00:41:35] Warning: The file properties have changed:
[00:41:35]          File: /usr/bin/perl
[00:41:35]          Current hash: c980066b572f250b51f59ccdd75b8321a8e164523e9edfa6ea876d45d832e91c
[00:41:35]          Stored hash : 35825ede4da1106b1cf0fc63191c86b9cd14a446c7fc5ae0f53779025719f460
[00:41:35]          Current inode: 12714158    Stored inode: 12714913
[00:41:35]          Current size: 1742800    Stored size: 1739120
[00:41:35]          Current file modification time: 1456852740 (01-Mär-2016 18:19:00)
[00:41:35]          Stored file modification time : 1431625758 (14-Mai-2015 19:49:18)
[00:41:35]  /usr/bin/pgrep                                  [ OK ]
[00:41:35]  /usr/bin/pkill                                  [ OK ]
[00:41:36]  /usr/bin/pstree                                [ OK ]
[00:41:36]  /usr/bin/rkhunter                              [ OK ]
[00:41:36]  /usr/bin/runcon                                [ OK ]
[00:41:36]  /usr/bin/sha1sum                                [ OK ]
[00:41:37]  /usr/bin/sha224sum                              [ OK ]
[00:41:37]  /usr/bin/sha256sum                              [ OK ]
[00:41:37]  /usr/bin/sha384sum                              [ OK ]
[00:41:37]  /usr/bin/sha512sum                              [ OK ]
[00:41:37]  /usr/bin/size                                  [ Warning ]
[00:41:37] Warning: The file properties have changed:
[00:41:37]          File: /usr/bin/size
[00:41:38]          Current hash: fd068f1b22fd74204858cff7f3b3e3a493a1971c0c70802582ae39362f7ff705
[00:41:38]          Stored hash : d0286b512b60fd985b59f34b279f4189cff5c5e507c97fc9fd8ec0b6083dc4ca
[00:41:38]          Current inode: 12720013    Stored inode: 12715174
[00:41:38]          Current file modification time: 1445450142 (21-Okt-2015 19:55:42)
[00:41:38]          Stored file modification time : 1444464508 (10-Okt-2015 10:08:28)
[00:41:38]  /usr/bin/sort                                  [ OK ]
[00:41:38]  /usr/bin/ssh                                    [ Warning ]
[00:41:38] Warning: The file properties have changed:
[00:41:38]          File: /usr/bin/ssh
[00:41:38]          Current hash: 2b5d0118c7b5401b8466683564662e0799752952b8f537b18fae638a491c45af
[00:41:38]          Stored hash : 885edd8fe917c30cfbe4b07b46b4bc22f27994d6a584efec8ae8eeeb3d2c7eda
[00:41:38]          Current inode: 12715389    Stored inode: 12715199
[00:41:38]          Current file modification time: 1452703368 (13-Jan-2016 17:42:48)
[00:41:38]          Stored file modification time : 1441964023 (11-Sep-2015 11:33:43)
[00:41:38]  /usr/bin/stat                                  [ OK ]
[00:41:38]  /usr/bin/strace                                [ OK ]
[00:41:39]  /usr/bin/strings                                [ Warning ]
[00:41:39] Warning: The file properties have changed:
[00:41:39]          File: /usr/bin/strings
[00:41:39]          Current hash: d021a5d313adc2edbb7e5baaa8b75a6db8b888ede9a784679642b0e060719e02
[00:41:39]          Stored hash : a99840c71c5e98f8be825bdb3af40f51682cff1b7e3283fd9007fc7a4e567d5f
[00:41:39]          Current inode: 12720015    Stored inode: 12715212
[00:41:39]          Current file modification time: 1445450142 (21-Okt-2015 19:55:42)
[00:41:39]          Stored file modification time : 1444464508 (10-Okt-2015 10:08:28)
[00:41:39]  /usr/bin/sudo                                  [ OK ]
[00:41:39]  /usr/bin/tail                                  [ OK ]
[00:41:40]  /usr/bin/telnet                                [ OK ]
[00:41:40]  /usr/bin/test                                  [ OK ]
[00:41:40]  /usr/bin/top                                    [ OK ]
[00:41:40]  /usr/bin/touch                                  [ OK ]
[00:41:41]  /usr/bin/tr                                    [ OK ]
[00:41:41]  /usr/bin/uniq                                  [ OK ]
[00:41:41]  /usr/bin/users                                  [ OK ]
[00:41:41]  /usr/bin/vmstat                                [ OK ]
[00:41:41]  /usr/bin/w                                      [ OK ]
[00:41:41]  /usr/bin/watch                                  [ OK ]
[00:41:42]  /usr/bin/wc                                    [ OK ]
[00:41:42]  /usr/bin/wget                                  [ OK ]
[00:41:42]  /usr/bin/whatis                                [ OK ]
[00:41:42]  /usr/bin/whereis                                [ OK ]
[00:41:42]  /usr/bin/which                                  [ OK ]
[00:41:43]  /usr/bin/who                                    [ OK ]
[00:41:43]  /usr/bin/whoami                                [ OK ]
[00:41:43]  /usr/bin/unhide                                [ OK ]
[00:41:43]  /usr/bin/mawk                                  [ OK ]
[00:41:44]  /usr/bin/lwp-request                            [ OK ]
[00:41:44]  /usr/bin/bsd-mailx                              [ OK ]
[00:41:44]  /usr/bin/telnet.netkit                          [ OK ]
[00:41:44]  /usr/bin/w.procps                              [ OK ]
[00:41:45]  /sbin/depmod                                    [ OK ]
[00:41:46]  /sbin/fsck                                      [ OK ]
[00:41:47]  /sbin/ifconfig                                  [ OK ]
[00:41:47]  /sbin/ifdown                                    [ Warning ]
[00:41:47] Warning: The file properties have changed:
[00:41:47]          File: /sbin/ifdown
[00:41:47]          Current hash: 651db729c5f8677f4c8827bb24c712892b2d7c8becc763e49d98b5232f1452e2
[00:41:47]          Stored hash : 6484df5d9545ec0f788ea36b0c8e24b787f58f0fcc9a414e2e40692c55e05d4c
[00:41:47]          Current inode: 23855359    Stored inode: 23855172
[00:41:47]          Current file modification time: 1456422700 (25-Feb-2016 18:51:40)
[00:41:47]          Stored file modification time : 1458114793 (16-Mär-2016 08:53:13)
[00:41:47]  /sbin/ifup                                      [ Warning ]
[00:41:48] Warning: The file properties have changed:
[00:41:48]          File: /sbin/ifup
[00:41:48]          Current hash: 651db729c5f8677f4c8827bb24c712892b2d7c8becc763e49d98b5232f1452e2
[00:41:48]          Stored hash : 6484df5d9545ec0f788ea36b0c8e24b787f58f0fcc9a414e2e40692c55e05d4c
[00:41:48]          Current inode: 23855162    Stored inode: 23855174
[00:41:48]          Current size: 63184    Stored size: 59440
[00:41:48]          Current file modification time: 1456422701 (25-Feb-2016 18:51:41)
[00:41:48]          Stored file modification time : 1436504199 (10-Jul-2015 06:56:39)
[00:41:48]  /sbin/init                                      [ OK ]
[00:41:48]  /sbin/insmod                                    [ OK ]
[00:41:48]  /sbin/ip                                        [ OK ]
[00:41:49]  /sbin/lsmod                                    [ OK ]
[00:41:50]  /sbin/modinfo                                  [ OK ]
[00:41:51]  /sbin/modprobe                                  [ OK ]
[00:41:52]  /sbin/rmmod                                    [ OK ]
[00:41:52]  /sbin/route                                    [ OK ]
[00:41:53]  /sbin/runlevel                                  [ OK ]
[00:41:55]  /sbin/sulogin                                  [ OK ]
[00:41:55]  /sbin/sysctl                                    [ OK ]
[00:41:57]  /bin/bash                                      [ OK ]
[00:41:57]  /bin/cat                                        [ OK ]
[00:41:58]  /bin/chmod                                      [ OK ]
[00:41:58]  /bin/chown                                      [ OK ]
[00:41:58]  /bin/cp                                        [ OK ]
[00:41:58]  /bin/date                                      [ OK ]
[00:41:59]  /bin/df                                        [ OK ]
[00:41:59]  /bin/dmesg                                      [ OK ]
[00:41:59]  /bin/echo                                      [ OK ]
[00:41:59]  /bin/ed                                        [ OK ]
[00:42:00]  /bin/egrep                                      [ OK ]
[00:42:00] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[00:42:00]  /bin/fgrep                                      [ OK ]
[00:42:00] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[00:42:00]  /bin/fuser                                      [ OK ]
[00:42:00]  /bin/grep                                      [ OK ]
[00:42:01]  /bin/ip                                        [ OK ]
[00:42:01]  /bin/kill                                      [ OK ]
[00:42:01]  /bin/less                                      [ OK ]
[00:42:02]  /bin/login                                      [ OK ]
[00:42:02]  /bin/ls                                        [ OK ]
[00:42:02]  /bin/lsmod                                      [ OK ]
[00:42:02]  /bin/mktemp                                    [ OK ]
[00:42:03]  /bin/more                                      [ OK ]
[00:42:03]  /bin/mount                                      [ OK ]
[00:42:03]  /bin/mv                                        [ OK ]
[00:42:04]  /bin/netstat                                    [ OK ]
[00:42:04]  /bin/ping                                      [ OK ]
[00:42:04]  /bin/ps                                        [ OK ]
[00:42:04]  /bin/pwd                                        [ OK ]
[00:42:05]  /bin/readlink                                  [ OK ]
[00:42:05]  /bin/sed                                        [ OK ]
[00:42:05]  /bin/sh                                        [ OK ]
[00:42:06]  /bin/su                                        [ OK ]
[00:42:06]  /bin/touch                                      [ OK ]
[00:42:07]  /bin/uname                                      [ OK ]
[00:42:07]  /bin/which                                      [ OK ]
[00:42:07] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[00:42:07]  /bin/kmod                                      [ OK ]
[00:42:08]  /bin/systemd                                    [ OK ]
[00:42:08]  /bin/systemctl                                  [ OK ]
[00:42:08]  /bin/dash                                      [ OK ]
[00:42:13]  /lib/systemd/systemd                            [ OK ]
[00:42:23]
[00:42:23] Info: Starting test name 'rootkits'
[00:42:23] Checking for rootkits...
[00:42:23]
[00:42:23] Info: Starting test name 'known_rkts'
[00:42:23] Performing check of known rootkit files and directories
[00:42:23]
[00:42:23] Checking for 55808 Trojan - Variant A...
[00:42:23]  Checking for file '/tmp/.../r'                  [ Not found ]
[00:42:23]  Checking for file '/tmp/.../a'                  [ Not found ]
[00:42:23] 55808 Trojan - Variant A                          [ Not found ]
[00:42:24]
[00:42:24] Checking for ADM Worm...
[00:42:24]  Checking for string 'w0rm'                      [ Not found ]
[00:42:24] ADM Worm                                          [ Not found ]
[00:42:24]
[00:42:24] Checking for AjaKit Rootkit...
[00:42:24]  Checking for file '/dev/tux/.addr'              [ Not found ]
[00:42:24]  Checking for file '/dev/tux/.proc'              [ Not found ]
[00:42:24]  Checking for file '/dev/tux/.file'              [ Not found ]
[00:42:24]  Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[00:42:24]  Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[00:42:24]  Checking for file '/lib/.libgh-gh/sb0k'        [ Not found ]
[00:42:24]  Checking for directory '/dev/tux'              [ Not found ]
[00:42:24]  Checking for directory '/lib/.libgh-gh'        [ Not found ]
[00:42:24] AjaKit Rootkit                                    [ Not found ]
[00:42:25]
[00:42:25] Checking for Adore Rootkit...
[00:42:25]  Checking for file '/usr/secure'                [ Not found ]
[00:42:25]  Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[00:42:25]  Checking for file '/usr/doc/sys/run'            [ Not found ]
[00:42:25]  Checking for file '/usr/doc/sys/crond'          [ Not found ]
[00:42:25]  Checking for file '/usr/sbin/kfd'              [ Not found ]
[00:42:25]  Checking for file '/usr/doc/kern/var'          [ Not found ]
[00:42:25]  Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[00:42:25]  Checking for file '/usr/doc/kern/ava'          [ Not found ]
[00:42:25]  Checking for file '/usr/doc/kern/adore.o'      [ Not found ]
[00:42:25]  Checking for file '/var/log/ssh/old'            [ Not found ]
[00:42:25]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[00:42:25]  Checking for directory '/usr/doc/kern'          [ Not found ]
[00:42:25]  Checking for directory '/usr/doc/backup'        [ Not found ]
[00:42:25]  Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[00:42:25]  Checking for directory '/lib/backup'            [ Not found ]
[00:42:26]  Checking for directory '/lib/backup/txt'        [ Not found ]
[00:42:26]  Checking for directory '/usr/doc/work'          [ Not found ]
[00:42:26]  Checking for directory '/usr/doc/sys'          [ Not found ]
[00:42:26]  Checking for directory '/var/log/ssh'          [ Not found ]
[00:42:26]  Checking for directory '/usr/doc/.spool'        [ Not found ]
[00:42:26]  Checking for directory '/usr/lib/kterm'        [ Not found ]
[00:42:26] Adore Rootkit                                    [ Not found ]
[00:42:26]
[00:42:26] Checking for aPa Kit...
[00:42:26]  Checking for file '/usr/share/.aPa'            [ Not found ]
[00:42:26] aPa Kit                                          [ Not found ]
[00:42:26]
[00:42:26] Checking for Apache Worm...
[00:42:26]  Checking for file '/bin/.log'                  [ Not found ]
[00:42:26] Apache Worm                                      [ Not found ]
[00:42:26]
[00:42:26] Checking for Ambient (ark) Rootkit...
[00:42:26]  Checking for file '/usr/lib/.ark?'              [ Not found ]
[00:42:27]  Checking for file '/dev/ptyxx/.log'            [ Not found ]
[00:42:27]  Checking for file '/dev/ptyxx/.file'            [ Not found ]
[00:42:27]  Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[00:42:27]  Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[00:42:27]  Checking for directory '/dev/ptyxx'            [ Not found ]
[00:42:27] Ambient (ark) Rootkit                            [ Not found ]
[00:42:27]
[00:42:27] Checking for Balaur Rootkit...
[00:42:27]  Checking for file '/usr/lib/liblog.o'          [ Not found ]
[00:42:27]  Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[00:42:27]  Checking for directory '/usr/lib/.egcs'        [ Not found ]
[00:42:27]  Checking for directory '/usr/lib/.wormie'      [ Not found ]
[00:42:27] Balaur Rootkit                                    [ Not found ]
[00:42:27]
[00:42:27] Checking for BeastKit Rootkit...
[00:42:27]  Checking for file '/usr/sbin/arobia'            [ Not found ]
[00:42:27]  Checking for file '/usr/sbin/idrun'            [ Not found ]
[00:42:27]  Checking for file '/usr/lib/elm/arobia/elm'    [ Not found ]
[00:42:27]  Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[00:42:28]  Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[00:42:28]  Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[00:42:28]  Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[00:42:28]  Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[00:42:28]  Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[00:42:28]  Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[00:42:28] BeastKit Rootkit                                  [ Not found ]
[00:42:28]
[00:42:28] Checking for beX2 Rootkit...
[00:42:28]  Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[00:42:28]  Checking for file '/usr/bin/sshd2'              [ Not found ]
[00:42:28]  Checking for directory '/usr/include/bex'      [ Not found ]
[00:42:28] beX2 Rootkit                                      [ Not found ]
[00:42:28]
[00:42:28] Checking for BOBKit Rootkit...
[00:42:28]  Checking for file '/usr/sbin/ntpsx'            [ Not found ]
[00:42:28]  Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[00:42:28]  Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[00:42:28]  Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[00:42:28]  Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../proc.h'    [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../.bash_history' [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../bkit-get'  [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[00:42:28]  Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[00:42:28]  Checking for file '/usr/lib/.../bkit-adore.o'  [ Not found ]
[00:42:28]  Checking for file '/usr/lib/.../ls'            [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../netstat'        [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../lsof'          [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../psr'            [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../find'          [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../pstree'        [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../slocate'        [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../du'            [ Not found ]
[00:42:29]  Checking for file '/usr/lib/.../top'            [ Not found ]
[00:42:29]  Checking for directory '/usr/sbin/...'          [ Not found ]
[00:42:29]  Checking for directory '/usr/include/...'      [ Not found ]
[00:42:29]  Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[00:42:29]  Checking for directory '/usr/lib/...'          [ Not found ]
[00:42:29]  Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[00:42:29]  Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[00:42:29]  Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[00:42:29]  Checking for directory '/tmp/.bkp'              [ Not found ]
[00:42:29] BOBKit Rootkit                                    [ Not found ]
[00:42:30]
[00:42:30] Checking for cb Rootkit...
[00:42:30]  Checking for file '/dev/srd0'                  [ Not found ]
[00:42:30]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[00:42:30]  Checking for file '/dev/mounnt'                [ Not found ]
[00:42:30]  Checking for file '/etc/rc.d/init.d/init'      [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/cl'    [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/wted'  [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/scan'  [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/sc'    [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/sl2'  [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/wu'    [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/v'    [ Not found ]
[00:42:30]  Checking for file '/usr/bin/.zeen/..<SP>/read'  [ Not found ]
[00:42:30]  Checking for file '/usr/lib/sshrc'              [ Not found ]
[00:42:30]  Checking for file '/usr/lib/ssh_host_key'      [ Not found ]
[00:42:30]  Checking for file '/usr/lib/ssh_host_key.pub'  [ Not found ]
[00:42:30]  Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[00:42:31]  Checking for file '/usr/lib/sshd_config'        [ Not found ]
[00:42:31]  Checking for file '/usr/lib/shosts.equiv'      [ Not found ]
[00:42:31]  Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[00:42:31]  Checking for file '/u/zappa/.ssh/pid'          [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[00:42:31]  Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[00:42:31]  Checking for directory '/usr/bin/.zeen'        [ Not found ]
[00:42:31]  Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[00:42:31]  Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[00:42:31]  Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[00:42:31] cb Rootkit                                        [ Not found ]
[00:42:31]
[00:42:31] Checking for CiNIK Worm (Slapper.B variant)...
[00:42:31]  Checking for file '/tmp/.cinik'                [ Not found ]
[00:42:31]  Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[00:42:31] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[00:42:31]
[00:42:31] Checking for Danny-Boy's Abuse Kit...
[00:42:31]  Checking for file '/dev/mdev'                  [ Not found ]
[00:42:32]  Checking for file '/usr/lib/libX.a'            [ Not found ]
[00:42:32] Danny-Boy's Abuse Kit                            [ Not found ]
[00:42:32]
[00:42:32] Checking for Devil RootKit...
[00:42:32]  Checking for file '/var/lib/games/.src'        [ Not found ]
[00:42:32]  Checking for file '/dev/dsx'                    [ Not found ]
[00:42:32]  Checking for file '/dev/caca'                  [ Not found ]
[00:42:32]  Checking for file '/dev/pro'                    [ Not found ]
[00:42:32]  Checking for file '/bin/bye'                    [ Not found ]
[00:42:32]  Checking for file '/bin/homedir'                [ Not found ]
[00:42:32]  Checking for file '/usr/bin/xfss'              [ Not found ]
[00:42:32]  Checking for file '/usr/sbin/tzava'            [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[00:42:32]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[00:42:33]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[00:42:33]  Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[00:42:33] Devil RootKit                                    [ Not found ]
[00:42:33]
[00:42:33] Checking for Dica-Kit Rootkit...
[00:42:33]  Checking for file '/lib/.sso'                  [ Not found ]
[00:42:33]  Checking for file '/lib/.so'                    [ Not found ]
[00:42:33]  Checking for file '/var/run/...dica/clean'      [ Not found ]
[00:42:33]  Checking for file '/var/run/...dica/dxr'        [ Not found ]
[00:42:33]  Checking for file '/var/run/...dica/read'      [ Not found ]
[00:42:33]  Checking for file '/var/run/...dica/write'      [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/lf'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/xl'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/xdr'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/psg'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/secure'    [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/rdx'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/va'        [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[00:42:34]  Checking for file '/var/run/...dica/last.log'  [ Not found ]
[00:42:34]  Checking for file '/usr/bin/.etc'              [ Not found ]
[00:42:34]  Checking for file '/etc/sshd_config'            [ Not found ]
[00:42:34]  Checking for file '/etc/ssh_host_key'          [ Not found ]
[00:42:34]  Checking for file '/etc/ssh_random_seed'        [ Not found ]
[00:42:34]  Checking for directory '/var/run/...dica'      [ Not found ]
[00:42:34]  Checking for directory '/var/run/...dica/mh'    [ Not found ]
[00:42:34]  Checking for directory '/var/run/...dica/scan'  [ Not found ]
[00:42:34] Dica-Kit Rootkit                                  [ Not found ]
[00:42:34]
[00:42:34] Checking for Dreams Rootkit...
[00:42:34]  Checking for file '/dev/ttyoa'                  [ Not found ]
[00:42:34]  Checking for file '/dev/ttyof'                  [ Not found ]
[00:42:34]  Checking for file '/dev/ttyop'                  [ Not found ]
[00:42:35]  Checking for file '/usr/bin/sense'              [ Not found ]
[00:42:35]  Checking for file '/usr/bin/sl2'                [ Not found ]
[00:42:35]  Checking for file '/usr/bin/logclear'          [ Not found ]
[00:42:35]  Checking for file '/usr/bin/(swapd)'            [ Not found ]
[00:42:35]  Checking for file '/usr/bin/initrd'            [ Not found ]
[00:42:35]  Checking for file '/usr/bin/crontabs'          [ Not found ]
[00:42:35]  Checking for file '/usr/bin/snfs'              [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libsss'            [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libsnf.log'        [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libshtift/top'      [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libshtift/ps'      [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libshtift/netstat'  [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libshtift/ls'      [ Not found ]
[00:42:35]  Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[00:42:35]  Checking for file '/usr/include/linseed.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/linpid.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/linkey.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/linconf.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/iceseed.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/icepid.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/icekey.h'      [ Not found ]
[00:42:35]  Checking for file '/usr/include/iceconf.h'      [ Not found ]
[00:42:35]  Checking for directory '/dev/ida/.hpd'          [ Not found ]
[00:42:36]  Checking for directory '/usr/lib/libshtift'    [ Not found ]
[00:42:36] Dreams Rootkit                                    [ Not found ]
[00:42:36]
[00:42:36] Checking for Duarawkz Rootkit...
[00:42:36]  Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[00:42:36]  Checking for directory '/usr/bin/duarawkz'      [ Not found ]
[00:42:36] Duarawkz Rootkit                                  [ Not found ]
[00:42:36]
[00:42:36] Checking for Enye LKM...
[00:42:36]  Checking for file '/etc/.enyelkmHIDE^IT.ko'    [ Not found ]
[00:42:36]  Checking for file '/etc/.enyelkmOCULTAR.ko'    [ Not found ]
[00:42:36] Enye LKM                                          [ Not found ]
[00:42:36]
[00:42:36] Checking for Flea Linux Rootkit...
[00:42:36]  Checking for file '/etc/ld.so.hash'            [ Not found ]
[00:42:36]  Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[00:42:36]  Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[00:42:36]  Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[00:42:36]  Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[00:42:36]  Checking for file '/usr/bin/ssh2d'              [ Not found ]
[00:42:37]  Checking for file '/usr/lib/ldlibns.so'        [ Not found ]
[00:42:37]  Checking for file '/usr/lib/ldlibps.so'        [ Not found ]
[00:42:37]  Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
[00:42:37]  Checking for file '/usr/lib/ldlibdu.so'        [ Not found ]
[00:42:37]  Checking for file '/usr/lib/ldlibct.so'        [ Not found ]
[00:42:37]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[00:42:37]  Checking for directory '/dev/..0'              [ Not found ]
[00:42:37]  Checking for directory '/dev/..0/backup'        [ Not found ]
[00:42:37] Flea Linux Rootkit                                [ Not found ]
[00:42:37]
[00:42:37] Checking for Fu Rootkit...
[00:42:37]  Checking for file '/sbin/xc'                    [ Not found ]
[00:42:37]  Checking for file '/usr/include/ivtype.h'      [ Not found ]
[00:42:37]  Checking for file '/bin/.lib'                  [ Not found ]
[00:42:37] Fu Rootkit                                        [ Not found ]
[00:42:37]
[00:42:37] Checking for Fuck`it Rootkit...
[00:42:37]  Checking for file '/lib/libproc.so.2.0.7'      [ Not found ]
[00:42:37]  Checking for file '/dev/proc/.bash_profile'    [ Not found ]
[00:42:37]  Checking for file '/dev/proc/.bashrc'          [ Not found ]
[00:42:37]  Checking for file '/dev/proc/.cshrc'            [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/hax0r'      [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[00:42:37]  Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[00:42:37]  Checking for file '/usr/lib/libcps.a'          [ Not found ]
[00:42:38]  Checking for file '/usr/lib/libtty.a'          [ Not found ]
[00:42:38]  Checking for directory '/dev/proc'              [ Not found ]
[00:42:38]  Checking for directory '/dev/proc/fuckit'      [ Not found ]
[00:42:38]  Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[00:42:38]  Checking for directory '/dev/proc/toolz'        [ Not found ]
[00:42:38] Fuck`it Rootkit                                  [ Not found ]
[00:42:38]
[00:42:38] Checking for GasKit Rootkit...
[00:42:38]  Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
[00:42:38]  Checking for directory '/dev/dev'              [ Not found ]
[00:42:38]  Checking for directory '/dev/dev/gaskit'        [ Not found ]
[00:42:38]  Checking for directory '/dev/dev/gaskit/sshd'  [ Not found ]
[00:42:38] GasKit Rootkit                                    [ Not found ]
[00:42:38]
[00:42:38] Checking for Heroin LKM...
[00:42:38]  Checking for kernel symbol 'heroin'            [ Not found ]
[00:42:38] Heroin LKM                                        [ Not found ]
[00:42:38]
[00:42:38] Checking for HjC Kit...
[00:42:38]  Checking for directory '/dev/.hijackerz'        [ Not found ]
[00:42:39] HjC Kit                                          [ Not found ]
[00:42:39]
[00:42:39] Checking for ignoKit Rootkit...
[00:42:39]  Checking for file '/lib/defs/p'                [ Not found ]
[00:42:39]  Checking for file '/lib/defs/q'                [ Not found ]
[00:42:39]  Checking for file '/lib/defs/r'                [ Not found ]
[00:42:39]  Checking for file '/lib/defs/s'                [ Not found ]
[00:42:39]  Checking for file '/lib/defs/t'                [ Not found ]
[00:42:39]  Checking for file '/usr/lib/defs/p'            [ Not found ]
[00:42:39]  Checking for file '/usr/lib/defs/q'            [ Not found ]
[00:42:39]  Checking for file '/usr/lib/defs/r'            [ Not found ]
[00:42:39]  Checking for file '/usr/lib/defs/s'            [ Not found ]
[00:42:39]  Checking for file '/usr/lib/defs/t'            [ Not found ]
[00:42:39]  Checking for file '/usr/lib/.libigno/pkunsec'  [ Not found ]
[00:42:39]  Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[00:42:39]  Checking for directory '/usr/lib/.libigno'      [ Not found ]
[00:42:39]  Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[00:42:39] ignoKit Rootkit                                  [ Not found ]
[00:42:39]
[00:42:39] Checking for IntoXonia-NG Rootkit...
[00:42:40]  Checking for kernel symbol 'funces'            [ Not found ]
[00:42:40]  Checking for kernel symbol 'ixinit'            [ Not found ]
[00:42:40]  Checking for kernel symbol 'tricks'            [ Not found ]
[00:42:40]  Checking for kernel symbol 'kernel_unlink'      [ Not found ]
[00:42:40]  Checking for kernel symbol 'rootme'            [ Not found ]
[00:42:40]  Checking for kernel symbol 'hide_module'        [ Not found ]
[00:42:40]  Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
[00:42:40] IntoXonia-NG Rootkit                              [ Not found ]
[00:42:40]
[00:42:40] Checking for Irix Rootkit...
[00:42:40]  Checking for directory '/dev/pts/01'            [ Not found ]
[00:42:40]  Checking for directory '/dev/pts/01/backup'    [ Not found ]
[00:42:40]  Checking for directory '/dev/pts/01/etc'        [ Not found ]
[00:42:41]  Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[00:42:41] Irix Rootkit                                      [ Not found ]
[00:42:41]
[00:42:41] Checking for Jynx Rootkit...
[00:42:41]  Checking for file '/xochikit/bc'                [ Not found ]
[00:42:41]  Checking for file '/xochikit/ld_poison.so'      [ Not found ]
[00:42:41]  Checking for file '/omgxochi/bc'                [ Not found ]
[00:42:41]  Checking for file '/omgxochi/ld_poison.so'      [ Not found ]
[00:42:41]  Checking for file '/var/local/^^/bc'            [ Not found ]
[00:42:41]  Checking for file '/var/local/^^/ld_poison.so'  [ Not found ]
[00:42:41]  Checking for directory '/xochikit'              [ Not found ]
[00:42:41]  Checking for directory '/omgxochi'              [ Not found ]
[00:42:41]  Checking for directory '/var/local/^^'          [ Not found ]
[00:42:41] Jynx Rootkit                                      [ Not found ]
[00:42:41]
[00:42:41] Checking for KBeast Rootkit...
[00:42:41]  Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[00:42:41]  Checking for file '/usr/_h4x_/_h4x_bd'          [ Not found ]
[00:42:41]  Checking for file '/usr/_h4x_/acctlog'          [ Not found ]
[00:42:41]  Checking for directory '/usr/_h4x_'            [ Not found ]
[00:42:42]  Checking for kernel symbol 'h4x_delete_module'  [ Not found ]
[00:42:42]  Checking for kernel symbol 'h4x_getdents64'    [ Not found ]
[00:42:42]  Checking for kernel symbol 'h4x_kill'          [ Not found ]
[00:42:43]  Checking for kernel symbol 'h4x_open'          [ Not found ]
[00:42:43]  Checking for kernel symbol 'h4x_read'          [ Not found ]
[00:42:43]  Checking for kernel symbol 'h4x_rename'        [ Not found ]
[00:42:43]  Checking for kernel symbol 'h4x_rmdir'          [ Not found ]
[00:42:44]  Checking for kernel symbol 'h4x_tcp4_seq_show'  [ Not found ]
[00:42:44]  Checking for kernel symbol 'h4x_write'          [ Not found ]
[00:42:44] KBeast Rootkit                                    [ Not found ]
[00:42:44]
[00:42:44] Checking for Kitko Rootkit...
[00:42:45]  Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[00:42:45] Kitko Rootkit                                    [ Not found ]
[00:42:45]
[00:42:45] Checking for Knark Rootkit...
[00:42:45]  Checking for file '/proc/knark/pids'            [ Not found ]
[00:42:45]  Checking for directory '/proc/knark'            [ Not found ]
[00:42:45] Knark Rootkit                                    [ Not found ]
[00:42:45]
[00:42:45] Checking for ld-linuxv.so Rootkit...
[00:42:45]  Checking for file '/lib/ld-linuxv.so.1'        [ Not found ]
[00:42:45]  Checking for directory '/var/opt/_so_cache'    [ Not found ]
[00:42:45]  Checking for directory '/var/opt/_so_cache/ld'  [ Not found ]
[00:42:45]  Checking for directory '/var/opt/_so_cache/lc'  [ Not found ]
[00:42:45] ld-linuxv.so Rootkit                              [ Not found ]
[00:42:45]
[00:42:45] Checking for Li0n Worm...
[00:42:45]  Checking for file '/bin/in.telnetd'            [ Not found ]
[00:42:45]  Checking for file '/bin/mjy'                    [ Not found ]
[00:42:45]  Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[00:42:45]  Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[00:42:45]  Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[00:42:45]  Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/bind'    [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/1i0n.sh'      [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/lib/netstat'  [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[00:42:46]  Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[00:42:46] Li0n Worm                                        [ Not found ]
[00:42:46]
[00:42:46] Checking for Lockit / LJK2 Rootkit...
[00:42:46]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[00:42:47]  Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[00:42:48]  Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[00:42:48]  Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[00:42:48] Lockit / LJK2 Rootkit                            [ Not found ]
[00:42:48]
[00:42:48] Checking for Mood-NT Rootkit...
[00:42:48]  Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[00:42:48]  Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[00:42:48]  Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[00:42:48]  Checking for file '/_cthulhu/mood-nt.sniff'    [ Not found ]
[00:42:48]  Checking for directory '/_cthulhu'              [ Not found ]
[00:42:48] Mood-NT Rootkit                                  [ Not found ]
[00:42:48]
[00:42:48] Checking for MRK Rootkit...
[00:42:48]  Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[00:42:49]  Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[00:42:49]  Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[00:42:49]  Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[00:42:49]  Checking for directory '/dev/ida/.inet'        [ Not found ]
[00:42:49]  Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[00:42:49] MRK Rootkit                                      [ Not found ]
[00:42:49]
[00:42:49] Checking for Ni0 Rootkit...
[00:42:49]  Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[00:42:49]  Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[00:42:50]  Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[00:42:50]  Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[00:42:50]  Checking for directory '/tmp/waza'              [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[00:42:50]  Checking for directory '/usr/sbin/es'          [ Not found ]
[00:42:50] Ni0 Rootkit                                      [ Not found ]
[00:42:50]
[00:42:50] Checking for Ohhara Rootkit...
[00:42:50]  Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[00:42:50]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[00:42:51]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[00:42:51] Ohhara Rootkit                                    [ Not found ]
[00:42:51]
[00:42:51] Checking for Optic Kit (Tux) Worm...
[00:42:51]  Checking for directory '/dev/tux'              [ Not found ]
[00:42:51]  Checking for directory '/usr/bin/xchk'          [ Not found ]
[00:42:51]  Checking for directory '/usr/bin/xsf'          [ Not found ]
[00:42:52]  Checking for directory '/usr/bin/ssh2d'        [ Not found ]
[00:42:52] Optic Kit (Tux) Worm                              [ Not found ]
[00:42:52]
[00:42:52] Checking for Oz Rootkit...
[00:42:52]  Checking for file '/dev/.oz/.nap/rkit/terror'  [ Not found ]
[00:42:52]  Checking for directory '/dev/.oz'              [ Not found ]
[00:42:52] Oz Rootkit                                        [ Not found ]
[00:42:52]
[


dennissteins 17.03.2016 01:55

Code:

00:42:52] Checking for Phalanx Rootkit...
[00:42:52]  Checking for file '/uNFuNF'                    [ Not found ]
[00:42:52]  Checking for file '/etc/host.ph1'              [ Not found ]
[00:42:52]  Checking for file '/bin/host.ph1'              [ Not found ]
[00:42:53]  Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[00:42:53]  Checking for file '/usr/share/.home.ph1/cb'    [ Not found ]
[00:42:53]  Checking for file '/usr/share/.home.ph1/kebab'  [ Not found ]
[00:42:53]  Checking for directory '/usr/share/.home.ph1'  [ Not found ]
[00:42:53]  Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[00:42:53] Phalanx Rootkit                                  [ Not found ]
[00:42:53]
[00:42:53] Checking for Phalanx2 Rootkit...
[00:42:53]  Checking for file '/etc/khubd.p2/.p2rc'        [ Not found ]
[00:42:53]  Checking for file '/etc/khubd.p2/.phalanx2'    [ Not found ]
[00:42:53]  Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
[00:42:53]  Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
[00:42:53]  Checking for file '/etc/lolzz.p2/.p2rc'        [ Not found ]
[00:42:53]  Checking for file '/etc/lolzz.p2/.phalanx2'    [ Not found ]
[00:42:53]  Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
[00:42:54]  Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
[00:42:54]  Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[00:42:54]  Checking for file '/usr/lib/zupzz.p2/.p-2.3d'  [ Not found ]
[00:42:54]  Checking for file '/usr/lib/zupzz.p2/.p2rc'    [ Not found ]
[00:42:54]  Checking for directory '/etc/khubd.p2'          [ Not found ]
[00:42:55]  Checking for directory '/etc/lolzz.p2'          [ Not found ]
[00:42:55]  Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[00:42:55] Phalanx2 Rootkit                                  [ Not found ]
[00:42:55]
[00:42:55] Checking for Phalanx2 Rootkit (extended tests)...
[00:42:55]  Checking for directory '/etc/khubd.p2'          [ Not found ]
[00:42:55]  Checking for directory '/etc/lolzz.p2'          [ Not found ]
[00:42:55]  Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[00:42:55] Phalanx2 Rootkit (extended tests)                [ Not found ]
[00:42:55]
[00:42:55] Checking for Portacelo Rootkit...
[00:42:55]  Checking for file '/var/lib/.../.ak'            [ Not found ]
[00:42:55]  Checking for file '/var/lib/.../.hk'            [ Not found ]
[00:42:56]  Checking for file '/var/lib/.../.rs'            [ Not found ]
[00:42:56]  Checking for file '/var/lib/.../.p'            [ Not found ]
[00:42:56]  Checking for file '/var/lib/.../getty'          [ Not found ]
[00:42:56]  Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../show'          [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../nlkt.o'        [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../ssshrc'        [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../sssh_equiv'    [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[00:42:57]  Checking for file '/var/lib/.../sssh_pid'      [ Not found ]
[00:42:57]  Checking for file '~/.sssh/known_hosts'        [ Not found ]
[00:42:58] Portacelo Rootkit                                [ Not found ]
[00:42:58]
[00:42:58] Checking for R3dstorm Toolkit...
[00:42:58]  Checking for file '/var/log/tk02/see_all'      [ Not found ]
[00:42:58]  Checking for file '/var/log/tk02/.scris'        [ Not found ]
[00:42:58]  Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[00:42:58]  Checking for file '/bin/.../hate/sk'            [ Not found ]
[00:42:59]  Checking for file '/bin/.../see_all'            [ Not found ]
[00:42:59]  Checking for directory '/var/log/tk02'          [ Not found ]
[00:42:59]  Checking for directory '/var/log/tk02/old'      [ Not found ]
[00:42:59]  Checking for directory '/bin/...'              [ Not found ]
[00:42:59] R3dstorm Toolkit                                  [ Not found ]
[00:42:59]
[00:42:59] Checking for RH-Sharpe's Rootkit...
[00:42:59]  Checking for file '/bin/lps'                    [ Not found ]
[00:42:59]  Checking for file '/usr/bin/lpstree'            [ Not found ]
[00:43:00]  Checking for file '/usr/bin/ltop'              [ Not found ]
[00:43:00]  Checking for file '/usr/bin/lkillall'          [ Not found ]
[00:43:00]  Checking for file '/usr/bin/ldu'                [ Not found ]
[00:43:00]  Checking for file '/usr/bin/lnetstat'          [ Not found ]
[00:43:00]  Checking for file '/usr/bin/wp'                [ Not found ]
[00:43:00]  Checking for file '/usr/bin/shad'              [ Not found ]
[00:43:00]  Checking for file '/usr/bin/vadim'              [ Not found ]
[00:43:00]  Checking for file '/usr/bin/slice'              [ Not found ]
[00:43:01]  Checking for file '/usr/bin/cleaner'            [ Not found ]
[00:43:01]  Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[00:43:01] RH-Sharpe's Rootkit                              [ Not found ]
[00:43:01]
[00:43:01] Checking for RSHA's Rootkit...
[00:43:01]  Checking for file '/bin/kr4p'                  [ Not found ]
[00:43:01]  Checking for file '/usr/bin/n3tstat'            [ Not found ]
[00:43:02]  Checking for file '/usr/bin/chsh2'              [ Not found ]
[00:43:02]  Checking for file '/usr/bin/slice2'            [ Not found ]
[00:43:02]  Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[00:43:02]  Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[00:43:02]  Checking for directory '/etc/rc.d/rsha'        [ Not found ]
[00:43:02]  Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[00:43:02] RSHA's Rootkit                                    [ Not found ]
[00:43:02]
[00:43:02] Checking for Scalper Worm...
[00:43:03]  Checking for file '/tmp/.a'                    [ Not found ]
[00:43:03]  Checking for file '/tmp/.uua'                  [ Not found ]
[00:43:03] Scalper Worm                                      [ Not found ]
[00:43:04]
[00:43:04] Checking for Sebek LKM...
[00:43:04]  Checking for kernel symbol 'adore or sebek'    [ Not found ]
[00:43:05] Sebek LKM                                        [ Not found ]
[00:43:05]
[00:43:05] Checking for Shutdown Rootkit...
[00:43:05]  Checking for file '/usr/man/man5/..<SP>/.dir/scannah/asus' [ Not found ]
[00:43:05]  Checking for file '/usr/man/man5/..<SP>/.dir/see' [ Not found ]
[00:43:05]  Checking for file '/usr/man/man5/..<SP>/.dir/nscd' [ Not found ]
[00:43:05]  Checking for file '/usr/man/man5/..<SP>/.dir/alpd' [ Not found ]
[00:43:06]  Checking for file '/etc/rc.d/rc.local<SP>'      [ Not found ]
[00:43:06]  Checking for directory '/usr/man/man5/..<SP>/.dir' [ Not found ]
[00:43:06]  Checking for directory '/usr/man/man5/..<SP>/.dir/scannah' [ Not found ]
[00:43:06]  Checking for directory '/etc/rc.d/rc0.d/..<SP>/.dir' [ Not found ]
[00:43:06] Shutdown Rootkit                                  [ Not found ]
[00:43:07]
[00:43:07] Checking for SHV4 Rootkit...
[00:43:07]  Checking for file '/etc/ld.so.hash'            [ Not found ]
[00:43:07]  Checking for file '/lib/libext-2.so.7'          [ Not found ]
[00:43:07]  Checking for file '/lib/lidps1.so'              [ Not found ]
[00:43:07]  Checking for file '/lib/libproc.a'              [ Not found ]
[00:43:07]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[00:43:07]  Checking for file '/lib/ldd.so/tks'            [ Not found ]
[00:43:08]  Checking for file '/lib/ldd.so/tkp'            [ Not found ]
[00:43:08]  Checking for file '/lib/ldd.so/tksb'            [ Not found ]
[00:43:08]  Checking for file '/lib/security/.config/sshd'  [ Not found ]
[00:43:08]  Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[00:43:08]  Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[00:43:08]  Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[00:43:09]  Checking for file '/usr/include/file.h'        [ Not found ]
[00:43:09]  Checking for file '/usr/include/hosts.h'        [ Not found ]
[00:43:09]  Checking for file '/usr/include/lidps1.so'      [ Not found ]
[00:43:10]  Checking for file '/usr/include/log.h'          [ Not found ]
[00:43:10]  Checking for file '/usr/include/proc.h'        [ Not found ]
[00:43:10]  Checking for file '/usr/sbin/xntps'            [ Not found ]
[00:43:10]  Checking for file '/dev/srd0'                  [ Not found ]
[00:43:10]  Checking for directory '/lib/ldd.so'            [ Not found ]
[00:43:10]  Checking for directory '/lib/security/.config'  [ Not found ]
[00:43:10]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[00:43:11] SHV4 Rootkit                                      [ Not found ]
[00:43:11]
[00:43:11] Checking for SHV5 Rootkit...
[00:43:11]  Checking for file '/etc/sh.conf'                [ Not found ]
[00:43:12]  Checking for file '/lib/libproc.a'              [ Not found ]
[00:43:12]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[00:43:12]  Checking for file '/lib/lidps1.so'              [ Not found ]
[00:43:12]  Checking for file '/lib/libsh.so/bash'          [ Not found ]
[00:43:12]  Checking for file '/usr/include/file.h'        [ Not found ]
[00:43:12]  Checking for file '/usr/include/hosts.h'        [ Not found ]
[00:43:13]  Checking for file '/usr/include/log.h'          [ Not found ]
[00:43:13]  Checking for file '/usr/include/proc.h'        [ Not found ]
[00:43:13]  Checking for file '/lib/libsh.so/shdcf2'        [ Not found ]
[00:43:13]  Checking for file '/lib/libsh.so/shhk'          [ Not found ]
[00:43:14]  Checking for file '/lib/libsh.so/shhk.pub'      [ Not found ]
[00:43:14]  Checking for file '/lib/libsh.so/shrs'          [ Not found ]
[00:43:14]  Checking for file '/usr/lib/libsh/.bashrc'      [ Not found ]
[00:43:14]  Checking for file '/usr/lib/libsh/shsb'        [ Not found ]
[00:43:14]  Checking for file '/usr/lib/libsh/hide'        [ Not found ]
[00:43:14]  Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[00:43:15]  Checking for file '/usr/lib/libsh/.sniff/shp'  [ Not found ]
[00:43:15]  Checking for file '/dev/srd0'                  [ Not found ]
[00:43:15]  Checking for directory '/lib/libsh.so'          [ Not found ]
[00:43:15]  Checking for directory '/usr/lib/libsh'        [ Not found ]
[00:43:15]  Checking for directory '/usr/lib/libsh/utilz'  [ Not found ]
[00:43:15]  Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[00:43:16] SHV5 Rootkit                                      [ Not found ]
[00:43:16]
[00:43:16] Checking for Sin Rootkit...
[00:43:16]  Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[00:43:16]  Checking for file '/dev/ttyoa'                  [ Not found ]
[00:43:16]  Checking for file '/dev/ttyof'                  [ Not found ]
[00:43:16]  Checking for file '/dev/ttyop'                  [ Not found ]
[00:43:16]  Checking for file '/dev/ttyos'                  [ Not found ]
[00:43:17]  Checking for file '/usr/lib/.lib'              [ Not found ]
[00:43:17]  Checking for file '/usr/lib/sn/.X'              [ Not found ]
[00:43:17]  Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[00:43:17]  Checking for file '/usr/lib/ld/.X'              [ Not found ]
[00:43:17]  Checking for file '/usr/man/man1/...'          [ Not found ]
[00:43:17]  Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[00:43:18]  Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[00:43:18]  Checking for directory '/usr/lib/sn'            [ Not found ]
[00:43:18]  Checking for directory '/usr/lib/man1/...'      [ Not found ]
[00:43:18]  Checking for directory '/dev/.haos'            [ Not found ]
[00:43:18] Sin Rootkit                                      [ Not found ]
[00:43:18]
[00:43:18] Checking for Slapper Worm...
[00:43:19]  Checking for file '/tmp/.bugtraq'              [ Not found ]
[00:43:19]  Checking for file '/tmp/.uubugtraq'            [ Not found ]
[00:43:19]  Checking for file '/tmp/.bugtraq.c'            [ Not found ]
[00:43:19]  Checking for file '/tmp/httpd'                  [ Not found ]
[00:43:19]  Checking for file '/tmp/.unlock'                [ Not found ]
[00:43:20]  Checking for file '/tmp/update'                [ Not found ]
[00:43:20]  Checking for file '/tmp/.cinik'                [ Not found ]
[00:43:20]  Checking for file '/tmp/.b'                    [ Not found ]
[00:43:20] Slapper Worm                                      [ Not found ]
[00:43:20]
[00:43:20] Checking for Sneakin Rootkit...
[00:43:20]  Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[00:43:21] Sneakin Rootkit                                  [ Not found ]
[00:43:21]
[00:43:21] Checking for 'Spanish' Rootkit...
[00:43:21]  Checking for file '/dev/ptyq'                  [ Not found ]
[00:43:21]  Checking for file '/bin/ad'                    [ Not found ]
[00:43:21]  Checking for file '/bin/ava'                    [ Not found ]
[00:43:21]  Checking for file '/bin/server'                [ Not found ]
[00:43:21]  Checking for file '/usr/sbin/rescue'            [ Not found ]
[00:43:21]  Checking for file '/usr/share/.../chrps'        [ Not found ]
[00:43:22]  Checking for file '/usr/share/.../chrifconfig'  [ Not found ]
[00:43:22]  Checking for file '/usr/share/.../netstat'      [ Not found ]
[00:43:22]  Checking for file '/usr/share/.../linsniffer'  [ Not found ]
[00:43:22]  Checking for file '/usr/share/.../charbd'      [ Not found ]
[00:43:22]  Checking for file '/usr/share/.../charbd2'      [ Not found ]
[00:43:23]  Checking for file '/usr/share/.../charbd3'      [ Not found ]
[00:43:23]  Checking for file '/usr/share/.../charbd4'      [ Not found ]
[00:43:23]  Checking for file '/usr/man/tmp/update.tgz'    [ Not found ]
[00:43:23]  Checking for file '/var/lib/rpm/db.rpm'        [ Not found ]
[00:43:23]  Checking for file '/var/cache/man/.cat'        [ Not found ]
[00:43:23]  Checking for file '/var/spool/lpd/remote/.lpq'  [ Not found ]
[00:43:23]  Checking for directory '/usr/share/...'        [ Not found ]
[00:43:23] 'Spanish' Rootkit                                [ Not found ]
[00:43:24]
[00:43:24] Checking for Suckit Rootkit...
[00:43:24]  Checking for file '/sbin/initsk12'              [ Not found ]
[00:43:24]  Checking for file '/sbin/initxrk'              [ Not found ]
[00:43:24]  Checking for file '/usr/bin/null'              [ Not found ]
[00:43:24]  Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[00:43:25]  Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[00:43:26]  Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[00:43:26]  Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[00:43:26]  Checking for directory '/etc/.MG'              [ Not found ]
[00:43:26]  Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[00:43:26]  Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[00:43:26] Suckit Rootkit                                    [ Not found ]
[00:43:26]
[00:43:26] Checking for Superkit Rootkit...
[00:43:26]  Checking for file '/usr/man/.sman/sk/backsh'    [ Not found ]
[00:43:27]  Checking for file '/usr/man/.sman/sk/izbtrag'  [ Not found ]
[00:43:27]  Checking for file '/usr/man/.sman/sk/sksniff'  [ Not found ]
[00:43:27]  Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[00:43:27]  Checking for directory '/usr/man/.sman/sk'      [ Not found ]
[00:43:27] Superkit Rootkit                                  [ Not found ]
[00:43:28]
[00:43:28] Checking for TBD (Telnet BackDoor)...
[00:43:28]  Checking for file '/usr/lib/.tbd'              [ Not found ]
[00:43:28] TBD (Telnet BackDoor)                            [ Not found ]
[00:43:28]
[00:43:28] Checking for TeLeKiT Rootkit...
[00:43:29]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[00:43:29]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[00:43:29]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[00:43:29]  Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[00:43:29]  Checking for file '/dev/ptyr'                  [ Not found ]
[00:43:30]  Checking for file '/dev/ptyp'                  [ Not found ]
[00:43:30]  Checking for file '/dev/ptyq'                  [ Not found ]
[00:43:30]  Checking for file '/dev/hda06'                  [ Not found ]
[00:43:30]  Checking for file '/usr/info/libc1.so'          [ Not found ]
[00:43:31]  Checking for directory '/usr/man/man3/...'      [ Not found ]
[00:43:31]  Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[00:43:31]  Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[00:43:31] TeLeKiT Rootkit                                  [ Not found ]
[00:43:32]
[00:43:32] Checking for T0rn Rootkit...
[00:43:32]  Checking for file '/dev/.lib/lib/lib/t0rns'    [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/t0rnp'    [ Not found ]
[00:43:32]  Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/ssh.tgz'  [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/top'      [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/login'    [ Not found ]
[00:43:33]  Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[00:43:34]  Checking for file '/dev/.lib/lib/lib/1i0n.sh'  [ Not found ]
[00:43:34]  Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[00:43:34]  Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[00:43:34]  Checking for file '/dev/.lib/lib/lib/mjy'      [ Not found ]
[00:43:34]  Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[00:43:35]  Checking for file '/dev/.lib/lib/lib/tfn'      [ Not found ]
[00:43:35]  Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[00:43:35]  Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[00:43:36]  Checking for file '/usr/info/.torn/sh*'        [ Not found ]
[00:43:36]  Checking for file '/usr/src/.puta/.1addr'      [ Not found ]
[00:43:36]  Checking for file '/usr/src/.puta/.1file'      [ Not found ]
[00:43:36]  Checking for file '/usr/src/.puta/.1proc'      [ Not found ]
[00:43:36]  Checking for file '/usr/src/.puta/.1logz'      [ Not found ]
[00:43:36]  Checking for file '/usr/info/.t0rn'            [ Not found ]
[00:43:37]  Checking for directory '/dev/.lib'              [ Not found ]
[00:43:37]  Checking for directory '/dev/.lib/lib'          [ Not found ]
[00:43:37]  Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[00:43:37]  Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[00:43:38]  Checking for directory '/dev/.lib/lib/scan'    [ Not found ]
[00:43:38]  Checking for directory '/usr/src/.puta'        [ Not found ]
[00:43:38]  Checking for directory '/usr/man/man1/man1'    [ Not found ]
[00:43:38]  Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[00:43:38]  Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[00:43:38]  Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[00:43:38] T0rn Rootkit                                      [ Not found ]
[00:43:39]
[00:43:39] Checking for trNkit Rootkit...
[00:43:39]  Checking for file '/usr/lib/libbins.la'        [ Not found ]
[00:43:39]  Checking for file '/usr/lib/libtcs.so'          [ Not found ]
[00:43:39]  Checking for file '/dev/.ttpy/ulogin.sh'        [ Not found ]
[00:43:39]  Checking for file '/dev/.ttpy/tcpshell.sh'      [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/bupdu'            [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/buloc'            [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/buloc1'          [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/buloc2'          [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/stat'            [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/backps'          [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/tree'            [ Not found ]
[00:43:40]  Checking for file '/dev/.ttpy/topk'            [ Not found ]
[00:43:41]  Checking for file '/dev/.ttpy/wold'            [ Not found ]
[00:43:41]  Checking for file '/dev/.ttpy/whoold'          [ Not found ]
[00:43:41]  Checking for file '/dev/.ttpy/backdoors'        [ Not found ]
[00:43:41] trNkit Rootkit                                    [ Not found ]
[00:43:41]
[00:43:41] Checking for Trojanit Kit...
[00:43:41]  Checking for file '/bin/.ls'                    [ Not found ]
[00:43:41]  Checking for file '/bin/.ps'                    [ Not found ]
[00:43:42]  Checking for file '/bin/.netstat'              [ Not found ]
[00:43:42]  Checking for file '/usr/bin/.nop'              [ Not found ]
[00:43:42]  Checking for file '/usr/bin/.who'              [ Not found ]
[00:43:42] Trojanit Kit                                      [ Not found ]
[00:43:42]
[00:43:42] Checking for Tuxtendo Rootkit...
[00:43:42]  Checking for file '/lib/libproc.so.2.0.7'      [ Not found ]
[00:43:42]  Checking for file '/usr/bin/xchk'              [ Not found ]
[00:43:42]  Checking for file '/usr/bin/xsf'                [ Not found ]
[00:43:42]  Checking for file '/dev/tux/suidsh'            [ Not found ]
[00:43:42]  Checking for file '/dev/tux/.addr'              [ Not found ]
[00:43:42]  Checking for file '/dev/tux/.cron'              [ Not found ]
[00:43:43]  Checking for file '/dev/tux/.file'              [ Not found ]
[00:43:43]  Checking for file '/dev/tux/.log'              [ Not found ]
[00:43:43]  Checking for file '/dev/tux/.proc'              [ Not found ]
[00:43:43]  Checking for file '/dev/tux/.iface'            [ Not found ]
[00:43:43]  Checking for file '/dev/tux/.pw'                [ Not found ]
[00:43:44]  Checking for file '/dev/tux/.df'                [ Not found ]
[00:43:44]  Checking for file '/dev/tux/.ssh'              [ Not found ]
[00:43:44]  Checking for file '/dev/tux/.tux'              [ Not found ]
[00:43:44]  Checking for file '/dev/tux/ssh2/sshd2_config'  [ Not found ]
[00:43:45]  Checking for file '/dev/tux/ssh2/hostkey'      [ Not found ]
[00:43:45]  Checking for file '/dev/tux/ssh2/hostkey.pub'  [ Not found ]
[00:43:45]  Checking for file '/dev/tux/ssh2/logo'          [ Not found ]
[00:43:46]  Checking for file '/dev/tux/ssh2/random_seed'  [ Not found ]
[00:43:46]  Checking for file '/dev/tux/backup/crontab'    [ Not found ]
[00:43:46]  Checking for file '/dev/tux/backup/df'          [ Not found ]
[00:43:47]  Checking for file '/dev/tux/backup/dir'        [ Not found ]
[00:43:47]  Checking for file '/dev/tux/backup/find'        [ Not found ]
[00:43:47]  Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/locate'      [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/netstat'    [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/ps'          [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/syslogd'    [ Not found ]
[00:43:48]  Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[00:43:49]  Checking for file '/dev/tux/backup/top'        [ Not found ]
[00:43:49]  Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[00:43:49]  Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[00:43:49]  Checking for directory '/dev/tux'              [ Not found ]
[00:43:49]  Checking for directory '/dev/tux/ssh2'          [ Not found ]
[00:43:50]  Checking for directory '/dev/tux/backup'        [ Not found ]
[00:43:50] Tuxtendo Rootkit                                  [ Not found ]
[00:43:50]
[00:43:50] Checking for URK Rootkit...
[00:43:50]  Checking for file '/dev/prom/sn.l'              [ Not found ]
[00:43:50]  Checking for file '/usr/lib/ldlibps.so'        [ Not found ]
[00:43:51]  Checking for file '/usr/lib/ldlibnet.so'        [ Not found ]
[00:43:51]  Checking for file '/dev/pts/01/uconf.inv'      [ Not found ]
[00:43:51]  Checking for file '/dev/pts/01/cleaner'        [ Not found ]
[00:43:51]  Checking for file '/dev/pts/01/bin/psniff'      [ Not found ]
[00:43:51]  Checking for file '/dev/pts/01/bin/du'          [ Not found ]
[00:43:51]  Checking for file '/dev/pts/01/bin/ls'          [ Not found ]
[00:43:52]  Checking for file '/dev/pts/01/bin/passwd'      [ Not found ]
[00:43:52]  Checking for file '/dev/pts/01/bin/ps'          [ Not found ]
[00:43:52]  Checking for file '/dev/pts/01/bin/psr'        [ Not found ]
[00:43:52]  Checking for file '/dev/pts/01/bin/su'          [ Not found ]
[00:43:53]  Checking for file '/dev/pts/01/bin/find'        [ Not found ]
[00:43:53]  Checking for file '/dev/pts/01/bin/netstat'    [ Not found ]
[00:43:53]  Checking for file '/dev/pts/01/bin/ping'        [ Not found ]
[00:43:53]  Checking for file '/dev/pts/01/bin/strings'    [ Not found ]
[00:43:53]  Checking for file '/dev/pts/01/bin/bash'        [ Not found ]
[00:43:54]  Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[00:43:54]  Checking for file '/usr/man/man1/xxxxxxbin/ls'  [ Not found ]
[00:43:54]  Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[00:43:54]  Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[00:43:54]  Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[00:43:55]  Checking for file '/usr/man/man1/xxxxxxbin/su'  [ Not found ]
[00:43:55]  Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[00:43:55]  Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[00:43:55]  Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[00:43:56]  Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[00:43:56]  Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[00:43:56]  Checking for file '/tmp/conf.inv'              [ Not found ]
[00:43:56]  Checking for directory '/dev/prom'              [ Not found ]
[00:43:56]  Checking for directory '/dev/pts/01'            [ Not found ]
[00:43:56]  Checking for directory '/dev/pts/01/bin'        [ Not found ]
[00:43:57]  Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[00:43:57] URK Rootkit                                      [ Not found ]
[00:43:57]
[00:43:57] Checking for Vampire Rootkit...
[00:43:58]  Checking for kernel symbol 'new_getdents'      [ Not found ]
[00:43:58]  Checking for kernel symbol 'old_getdents'      [ Not found ]
[00:43:58]  Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[00:43:58]  Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[00:43:59] Vampire Rootkit                                  [ Not found ]
[00:43:59]
[00:43:59] Checking for VcKit Rootkit...
[00:43:59]  Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[00:43:59]  Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[00:43:59] VcKit Rootkit                                    [ Not found ]
[00:43:59]
[00:43:59] Checking for Volc Rootkit...
[00:43:59]  Checking for file '/usr/bin/volc'              [ Not found ]
[00:44:00]  Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[00:44:00]  Checking for file '/usr/lib/volc/linsniff'      [ Not found ]
[00:44:00]  Checking for file '/etc/rc.d/rc1.d/S25sysconf'  [ Not found ]
[00:44:00]  Checking for file '/etc/rc.d/rc2.d/S25sysconf'  [ Not found ]
[00:44:00]  Checking for file '/etc/rc.d/rc3.d/S25sysconf'  [ Not found ]
[00:44:00]  Checking for file '/etc/rc.d/rc4.d/S25sysconf'  [ Not found ]
[00:44:00]  Checking for file '/etc/rc.d/rc5.d/S25sysconf'  [ Not found ]
[00:44:00]  Checking for directory '/var/spool/.recent'    [ Not found ]
[00:44:01]  Checking for directory '/var/spool/.recent/.files' [ Not found ]
[00:44:01]  Checking for directory '/usr/lib/volc'          [ Not found ]
[00:44:01]  Checking for directory '/usr/lib/volc/backup'  [ Not found ]
[00:44:01] Volc Rootkit                                      [ Not found ]
[00:44:01]
[00:44:01] Checking for Xzibit Rootkit...
[00:44:01]  Checking for file '/dev/dsx'                    [ Not found ]
[00:44:02]  Checking for file '/dev/caca'                  [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/linsniffer'  [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/logclear'    [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/sense'        [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/sl2'          [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/sshdu'        [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/s'            [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[00:44:02]  Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[00:44:03]  Checking for file '/dev/ida/.inet/sl2new.c'    [ Not found ]
[00:44:03]  Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[00:44:03]  Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[00:44:03]  Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[00:44:03]  Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[00:44:03]  Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[00:44:03]  Checking for file '/www/cgi-bin/becys.cgi'      [ Not found ]
[00:44:04]  Checking for directory '/dev/ida/.inet'        [ Not found ]
[00:44:04] Xzibit Rootkit                                    [ Not found ]
[00:44:04]
[00:44:04] Checking for zaRwT.KiT Rootkit...
[00:44:04]  Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[00:44:04]  Checking for file '/dev/ttyf'                  [ Not found ]
[00:44:04]  Checking for file '/dev/ttyp'                  [ Not found ]
[00:44:05]  Checking for file '/dev/ttyn'                  [ Not found ]
[00:44:05]  Checking for file '/rk/tulz'                    [ Not found ]
[00:44:05]  Checking for directory '/rk'                    [ Not found ]
[00:44:05]  Checking for directory '/dev/rd/s'              [ Not found ]
[00:44:05] zaRwT.KiT Rootkit                                [ Not found ]
[00:44:05]
[00:44:05] Checking for ZK Rootkit...
[00:44:05]  Checking for file '/usr/share/.zk/zk'          [ Not found ]
[00:44:06]  Checking for file '/usr/X11R6/.zk/xfs'          [ Not found ]
[00:44:06]  Checking for file '/usr/X11R6/.zk/echo'        [ Not found ]
[00:44:06]  Checking for file '/etc/1ssue.net'              [ Not found ]
[00:44:06]  Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[00:44:07]  Checking for directory '/usr/share/.zk'        [ Not found ]
[00:44:07]  Checking for directory '/usr/X11R6/.zk'        [ Not found ]
[00:44:07] ZK Rootkit                                        [ Not found ]
[00:44:21]
[00:44:21] Info: Starting test name 'additional_rkts'
[00:44:21] Performing additional rootkit checks
[00:44:21]
[00:44:21]  Performing Suckit Rookit additional checks
[00:44:21]    Checking hard link count on '/sbin/init'      [ OK ]
[00:44:21]    Checking for hidden file extensions          [ None found ]
[00:44:21]    Running skdet command                        [ Skipped ]
[00:44:22] Info: Unable to find the 'skdet' command
[00:44:22]  Suckit Rookit additional checks                [ OK ]
[00:44:22]
[00:44:22] Info: Starting test name 'possible_rkt_files'
[00:44:22]  Performing check of possible rootkit files and directories
[00:44:22]    Checking for file '/dev/sdr0'                [ Not found ]
[00:44:23]    Checking for file '/dev/pisu'                [ Not found ]
[00:44:23]    Checking for file '/dev/xdta'                [ Not found ]
[00:44:23]    Checking for file '/dev/saux'                [ Not found ]
[00:44:23]    Checking for file '/dev/hdx'                  [ Not found ]
[00:44:24]    Checking for file '/dev/hdx1'                [ Not found ]
[00:44:24]    Checking for file '/dev/hdx2'                [ Not found ]
[00:44:24]    Checking for file '/dev/ptyy'                [ Not found ]
[00:44:24]    Checking for file '/dev/ptyu'                [ Not found ]
[00:44:24]    Checking for file '/dev/ptyv'                [ Not found ]
[00:44:25]    Checking for file '/dev/hdbb'                [ Not found ]
[00:44:25]    Checking for file '/tmp/.syshackfile'        [ Not found ]
[00:44:25]    Checking for file '/tmp/.bash_history'        [ Not found ]
[00:44:25]    Checking for file '/usr/info/.clib'          [ Not found ]
[00:44:26]    Checking for file '/usr/sbin/tcp.log'        [ Not found ]
[00:44:26]    Checking for file '/usr/bin/take/pid'        [ Not found ]
[00:44:26]    Checking for file '/sbin/create'              [ Not found ]
[00:44:26]    Checking for file '/dev/ttypz'                [ Not found ]
[00:44:26]    Checking for file '/var/log/tcp.log'          [ Not found ]
[00:44:26]    Checking for file '/usr/include/audit.h'      [ Not found ]
[00:44:26]    Checking for file '/usr/bin/sourcemask'      [ Not found ]
[00:44:26]    Checking for file '/usr/bin/ras2xm'          [ Not found ]
[00:44:26]    Checking for file '/dev/xmx'                  [ Not found ]
[00:44:27]    Checking for file '/usr/sbin/gpm.root'        [ Not found ]
[00:44:27]    Checking for file '/bin/vobiscum'            [ Not found ]
[00:44:27]    Checking for file '/bin/psr'                  [ Not found ]
[00:44:27]    Checking for file '/dev/kdx'                  [ Not found ]
[00:44:28]    Checking for file '/dev/dkx'                  [ Not found ]
[00:44:28]    Checking for file '/usr/sbin/sshd3'          [ Not found ]
[00:44:28]    Checking for file '/usr/sbin/jcd'            [ Not found ]
[00:44:28]    Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[00:44:28]    Checking for file '/usr/sbin/atd2'            [ Not found ]
[00:44:28]    Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[00:44:28]    Checking for file '/home/httpd/cgi-bin/psid'  [ Not found ]
[00:44:29]    Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[00:44:29]    Checking for file '/etc/rc.d/init.d/system'  [ Not found ]
[00:44:29]    Checking for file '/etc/rc.d/rc3.d/S93users'  [ Not found ]
[00:44:29]    Checking for file '/tmp/.ush'                [ Not found ]
[00:44:30]    Checking for file '/usr/lib/libhidefile.so'  [ Not found ]
[00:44:30]    Checking for file '/etc/cron.d/kmod'          [ Not found ]
[00:44:30]    Checking for file '/usr/lib/dmis/dmisd'      [ Not found ]
[00:44:30]    Checking for file '/lib/secure/libhij.so'    [ Not found ]
[00:44:30]    Checking for file '/usr/sbin/sshd3'          [ Not found ]
[00:44:30]    Checking for file '/etc/rc.d/init.d/crontab'  [ Not found ]
[00:44:30]    Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[00:44:31]    Checking for file '/usr/sbin/atd2'            [ Not found ]
[00:44:31]    Checking for file '/etc/rc.d/rc5.d/S93users'  [ Not found ]
[00:44:31]    Checking for file '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:44:31]    Checking for file '/etc/init.d/xfs3'          [ Not found ]
[00:44:32]    Checking for file '/usr/sbin/t.txt'          [ Not found ]
[00:44:32]    Checking for file '/usr/sbin/change'          [ Not found ]
[00:44:32]    Checking for file '/usr/sbin/s'              [ Not found ]
[00:44:32]    Checking for file '/bin/f'                    [ Not found ]
[00:44:33]    Checking for file '/bin/i'                    [ Not found ]
[00:44:33]    Checking for file '/lib/libncom.so.4.0.1'    [ Not found ]
[00:44:33]    Checking for file '/sbin/zinit'              [ Not found ]
[00:44:33]    Checking for file '/tmp/pass_ssh.log'        [ Not found ]
[00:44:34]    Checking for file '/usr/include/gpm2.h'      [ Not found ]
[00:44:34]    Checking for file '/etc/ssh/.sshd_auth'      [ Not found ]
[00:44:34]    Checking for file '/usr/lib/.sshd.h'          [ Not found ]
[00:44:34]    Checking for file '/var/run/.defunct'        [ Not found ]
[00:44:34]    Checking for file '/etc/httpd/run/.defunct'  [ Not found ]
[00:44:35]    Checking for file '/usr/share/pci.r'          [ Not found ]
[00:44:35]    Checking for file '/etc/cron.daily/dnsquery'  [ Not found ]
[00:44:35]    Checking for file '/usr/lib/libutil1.2.1.2.so' [ Not found ]
[00:44:36]    Checking for file '/bin/ceva'                [ Not found ]
[00:44:36]    Checking for file '/sbin/syslogd<SP>'        [ Not found ]
[00:44:36]    Checking for file '/usr/include/shup.h'      [ Not found ]
[00:44:36]    Checking for file '/etc/rpm/sshdOLD'          [ Not found ]
[00:44:36]    Checking for file '/etc/rpm/sshOLD'          [ Not found ]
[00:44:36]    Checking for file '/usr/share/passwd.h'      [ Not found ]
[00:44:36]    Checking for file '/lib/.xsyslog'            [ Not found ]
[00:44:37]    Checking for file '/etc/.xsyslog'            [ Not found ]
[00:44:37]    Checking for file '/lib/.ssyslog'            [ Not found ]
[00:44:37]    Checking for file '/tmp/.sendmail'            [ Not found ]
[00:44:37]    Checking for file '/usr/share/sshd.sync'      [ Not found ]
[00:44:38]    Checking for file '/bin/zcut'                [ Not found ]
[00:44:38]    Checking for file '/usr/bin/zmuie'            [ Not found ]
[00:44:38]    Checking for file '/lib/libkeyutils.so.1.9'  [ Not found ]
[00:44:38]    Checking for file '/lib64/libkeyutils.so.1.9' [ Not found ]
[00:44:38]    Checking for file '/usr/lib/libkeyutils.so.1.9' [ Not found ]
[00:44:38]    Checking for file '/usr/lib64/libkeyutils.so.1.9' [ Not found ]
[00:44:38]    Checking for directory '/dev/ptyas'          [ Not found ]
[00:44:39]    Checking for directory '/usr/bin/take'        [ Not found ]
[00:44:39]    Checking for directory '/usr/src/.lib'        [ Not found ]
[00:44:39]    Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[00:44:39]    Checking for directory '/lib/lblip.tk'        [ Not found ]
[00:44:40]    Checking for directory '/usr/sbin/...'        [ Not found ]
[00:44:40]    Checking for directory '/usr/share/.gun'      [ Not found ]
[00:44:40]    Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[00:44:40]    Checking for directory '/usr/man/man1/..<SP><SP>/.dir' [ Not found ]
[00:44:40]    Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[00:44:40]    Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[00:44:40]    Checking for directory '/tmp/.sys'            [ Not found ]
[00:44:40]    Checking for directory '/tmp/''              [ Not found ]
[00:44:41]    Checking for directory '/tmp/.,'              [ Not found ]
[00:44:41]    Checking for directory '/tmp/,.,'            [ Not found ]
[00:44:41]    Checking for directory '/dev/shm/emilien'    [ Not found ]
[00:44:41]    Checking for directory '/var/tmp/.log'        [ Not found ]
[00:44:41]    Checking for directory '/tmp/zmeu/...<SP>'    [ Not found ]
[00:44:42]    Checking for directory '/var/log/ssh'        [ Not found ]
[00:44:42]    Checking for directory '/dev/ida'            [ Not found ]
[00:44:42]    Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[00:44:42]    Checking for directory '/usr/lib/libshtift'  [ Not found ]
[00:44:42]    Checking for directory '/usr/src/.poop'      [ Not found ]
[00:44:42]    Checking for directory '/dev/wd4'            [ Not found ]
[00:44:43]    Checking for directory '/var/run/.tmp'        [ Not found ]
[00:44:43]    Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[00:44:43]    Checking for directory '/dev/portd'          [ Not found ]
[00:44:43]    Checking for directory '/dev/...'            [ Not found ]
[00:44:44]    Checking for directory '/usr/share/man/mansps' [ Not found ]
[00:44:44]    Checking for directory '/lib/.so'            [ Not found ]
[00:44:44]    Checking for directory '/lib/.sso'            [ Not found ]
[00:44:44]    Checking for directory '/usr/include/sslv3'  [ Not found ]
[00:44:45]    Checking for directory '/dev/shm/sshd'        [ Not found ]
[00:44:45]    Checking for directory '/usr/share/locale/mk/.dev/sk' [ Not found ]
[00:44:45]    Checking for directory '/usr/share/locale/mk/.dev' [ Not found ]
[00:44:46]    Checking for directory '/usr/include/netda.h' [ Not found ]
[00:44:46]    Checking for directory '/usr/include/.ssh'    [ Not found ]
[00:44:46]    Checking for directory '/usr/share/locale/jp/.<SP>' [ Not found ]
[00:44:46]    Checking for directory '/usr/share/.sqe'      [ Not found ]
[00:44:46]  Checking for possible rootkit files and directories [ None found ]
[00:44:46]
[00:44:46] Info: Starting test name 'possible_rkt_strings'
[00:44:46]  Performing check for possible rootkit strings
[00:44:46] Info: Using system startup paths: /etc/rc.local /etc/init.d
[00:44:47]    Checking for string 'phalanx'                [ Not found ]
[00:44:47]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[00:44:48]    Checking for string 'FUCK'                    [ Not found ]
[00:44:48]    Checking for string 'backdoor'                [ Not found ]
[00:44:48]    Checking for string '/usr/bin/rcpc'          [ Not found ]
[00:44:49]    Checking for string '/usr/sbin/login'        [ Not found ]
[00:44:49]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[00:44:49]    Checking for string 'vt200'                  [ Not found ]
[00:44:49]    Checking for string '/usr/bin/xstat'          [ Not found ]
[00:44:49]    Checking for string '/bin/envpc'              [ Not found ]
[00:44:50]    Checking for string 'L4m3r0x'                [ Not found ]
[00:44:50]    Checking for string '/lib/libext'            [ Not found ]
[00:44:50]    Checking for string '/usr/sbin/login'        [ Not found ]
[00:44:50]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[00:44:50]    Checking for string 'sendmail'                [ Not found ]
[00:44:51]    Checking for string 'cocacola'                [ Not found ]
[00:44:51]    Checking for string 'joao'                    [ Not found ]
[00:44:51]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[00:44:51]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[00:44:52]    Checking for string '/dev/sgk'                [ Not found ]
[00:44:52]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[00:44:52]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[00:44:52]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[00:44:53]    Checking for string '/lib/.sso'              [ Not found ]
[00:44:53]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[00:44:53]    Checking for string '/dev/caca'              [ Not found ]
[00:44:53]    Checking for string '/dev/ttyoa'              [ Not found ]
[00:44:53]    Checking for string '/usr/lib/ldlibns.so'    [ Not found ]
[00:44:54]    Checking for string '/dev/ptyxx/.addr'        [ Not found ]
[00:44:55]    Checking for string 'syg'                    [ Not found ]
[00:44:55]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[00:44:55]    Checking for string '/dev/pts/01'            [ Not found ]
[00:44:55]    Checking for string 'tw33dl3'                [ Not found ]
[00:44:55]    Checking for string 'psniff'                  [ Not found ]
[00:44:56]    Checking for string 'uconf.inv'              [ Not found ]
[00:44:56]    Checking for string 'lib/ldlibps.so'          [ Not found ]
[00:44:56]    Checking for string '/usr/lib/ldlibpst.so'    [ Not found ]
[00:44:56]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:44:56]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[00:44:57]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[00:44:57]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:44:57]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:44:57]    Checking for string '/bin/bash'              [ Not found ]
[00:44:59]    Checking for string '/dev/xdta'              [ Not found ]
[00:44:59]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[00:44:59]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[00:45:02]    Checking for string 'in.inetd'                [ Not found ]
[00:45:04]    Checking for string '#<HIDE_.*>'              [ Not found ]
[00:45:07]    Checking for string 'bin/xchk'                [ Not found ]
[00:45:09]    Checking for string 'bin/xsf'                [ Not found ]
[00:45:12]    Checking for string '/usr/bin/ssh2d'          [ Not found ]
[00:45:14]    Checking for string '/usr/sbin/xntps'        [ Not found ]
[00:45:17]    Checking for string 'ttyload'                [ Not found ]
[00:45:19]    Checking for string '/etc/rc.d/init.d/init'  [ Not found ]
[00:45:22]    Checking for string 'usr/bin/xfss'            [ Not found ]
[00:45:25]    Checking for string '/usr/sbin/rpc.netinet'  [ Not found ]
[00:45:27]    Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[00:45:29]    Checking for string '/usr/lib/.fx/xs'        [ Not found ]
[00:45:30]    Checking for string '/ssh2d'                  [ Not found ]
[00:45:31]    Checking for string '/dev/kmod'              [ Not found ]
[00:45:31]    Checking for string '/crth.o'                [ Not found ]
[00:45:32]    Checking for string '/crtz.o'                [ Not found ]
[00:45:33]    Checking for string '/dev/dos'                [ Not found ]
[00:45:33]    Checking for string '/lpq'                    [ Not found ]
[00:45:34]    Checking for string '/usr/sbin/rescue'        [ Not found ]
[00:45:35]    Checking for string '/usr/lib/lpstart'        [ Not found ]
[00:45:36]    Checking for string '/volc'                  [ Not found ]
[00:45:36]    Checking for string 'sourcemask'              [ Not found ]
[00:45:37]    Checking for string '/bin/vobiscum'          [ Not found ]
[00:45:38]    Checking for string '/usr/sbin/in.telnet'    [ Not found ]
[00:45:38]    Checking for string '/usr/bin/hdparm?-t1?-X53?-p' [ Not found ]
[00:45:39]    Checking for string '/lib/.xsyslog'          [ Not found ]
[00:45:40]    Checking for string '/etc/.xsyslog'          [ Not found ]
[00:45:41]    Checking for string '/lib/.ssyslog'          [ Not found ]
[00:45:41]    Checking for string '/tmp/.sendmail'          [ Not found ]
[00:45:41]    Checking for string '/lib/ldd.so/tkps'        [ Not found ]
[00:45:41]    Checking for string 't0rnkit'                [ Not found ]
[00:45:42]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[00:45:42]    Checking for string 'backdoor.h'              [ Not found ]
[00:45:42]    Checking for string 'backdoor_active'        [ Not found ]
[00:45:42]    Checking for string 'magic_pass_active'      [ Not found ]
[00:45:42]    Checking for string '/usr/include/gpm2.h'    [ Not found ]
[00:45:42]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:45:42]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:45:42]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:45:42]    Checking for string '/usr/lib/ldlibct.so'    [ Not found ]
[00:45:42]    Checking for string '/usr/lib/ldlibdu.so'    [ Not found ]
[00:45:42]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[00:45:42]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[00:45:42]    Checking for string '/dev/ida/.inet'          [ Not found ]
[00:45:42]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:42]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:42]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:42]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:43]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:43]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[00:45:43]    Checking for string 'backconnect'            [ Not found ]
[00:45:43]    Checking for string 'magic?packet?received'  [ Not found ]
[00:45:43]  Checking for possible rootkit strings          [ None found ]
[00:45:43]
[00:45:43] Info: Starting test name 'malware'
[00:45:43] Performing malware checks
[00:45:43]
[00:45:43] Info: Test 'deleted_files' disabled at users request.
[00:45:43]
[00:45:43] Info: Starting test name 'running_procs'
[00:45:47]  Checking running processes for suspicious files [ None found ]
[00:45:48]
[00:45:48] Info: Test 'hidden_procs' disabled at users request.
[00:45:48]
[00:45:48] Info: Test 'suspscan' disabled at users request.
[00:45:48]
[00:45:48] Info: Starting test name 'other_malware'
[00:45:48]  Performing check for login backdoors
[00:45:48]    Checking for '/bin/.login'                    [ Not found ]
[00:45:48]    Checking for '/sbin/.login'                  [ Not found ]
[00:45:48]  Checking for login backdoors                    [ None found ]
[00:45:48]
[00:45:48]  Performing check for suspicious directories
[00:45:48]    Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[00:45:49]    Checking for directory '/dev/rd/cdb'          [ Not found ]
[00:45:49]  Checking for suspicious directories            [ None found ]
[00:45:49]
[00:45:49]  Checking for software intrusions                [ Skipped ]
[00:45:49] Info: Check skipped - tripwire not installed
[00:45:49]
[00:45:49]  Performing check for sniffer log files
[00:45:49]    Checking for file '/usr/lib/libice.log'      [ Not found ]
[00:45:49]    Checking for file '/dev/prom/sn.l'            [ Not found ]
[00:45:49]    Checking for file '/dev/fd/.88/zxsniff.log'  [ Not found ]
[00:45:49]  Checking for sniffer log files                  [ None found ]
[00:45:49]
[00:45:49] Suspicious Shared Memory segments
[00:45:50]  Suspicious Shared Memory segments              [ None found ]
[00:45:50]
[00:45:50] Info: Starting test name 'trojans'
[00:45:50] Performing trojan specific checks
[00:45:50] Info: Using inetd configuration file '/etc/inetd.conf'
[00:45:50]  Checking for enabled inetd services            [ OK ]
[00:45:50]
[00:45:50]  Performing check for enabled xinetd services
[00:45:50]  Checking for enabled xinetd services            [ Skipped ]
[00:45:51] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[00:45:51] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[00:45:51]
[00:45:51] Info: Starting test name 'os_specific'
[00:45:51] Performing Linux specific checks
[00:45:51]  Checking loaded kernel modules                  [ OK ]
[00:45:51] Info: Using modules pathname of '/lib/modules/4.2.0-34-generic'
[00:45:52]  Checking kernel module names                    [ OK ]
[00:49:12]
[00:49:12] Info: Starting test name 'network'
[00:49:12] Checking the network...
[00:49:12]
[00:49:12] Performing checks on the network ports
[00:49:12] Info: Starting test name 'ports'
[00:49:12]  Performing check for backdoor ports
[00:49:13]    Checking for TCP port 1524                    [ Not found ]
[00:49:14]    Checking for TCP port 1984                    [ Not found ]
[00:49:14]    Checking for UDP port 2001                    [ Not found ]
[00:49:14]    Checking for TCP port 2006                    [ Not found ]
[00:49:15]    Checking for TCP port 2128                    [ Not found ]
[00:49:15]    Checking for TCP port 6666                    [ Not found ]
[00:49:15]    Checking for TCP port 6667                    [ Not found ]
[00:49:16]    Checking for TCP port 6668                    [ Not found ]
[00:49:17]    Checking for TCP port 6669                    [ Not found ]
[00:49:18]    Checking for TCP port 7000                    [ Not found ]
[00:49:18]    Checking for TCP port 13000                  [ Not found ]
[00:49:18]    Checking for TCP port 14856                  [ Not found ]
[00:49:19]    Checking for TCP port 25000                  [ Not found ]
[00:49:20]    Checking for TCP port 29812                  [ Not found ]
[00:49:20]    Checking for TCP port 31337                  [ Not found ]
[00:49:21]    Checking for TCP port 32982                  [ Not found ]
[00:49:22]    Checking for TCP port 33369                  [ Not found ]
[00:49:23]    Checking for TCP port 47107                  [ Not found ]
[00:49:23]    Checking for TCP port 47018                  [ Not found ]
[00:49:24]    Checking for TCP port 60922                  [ Not found ]
[00:49:24]    Checking for TCP port 62883                  [ Not found ]
[00:49:25]    Checking for TCP port 65535                  [ Not found ]
[00:49:25]  Checking for backdoor ports                    [ None found ]
[00:49:26]
[00:49:26] Info: Starting test name 'hidden_ports'
[00:49:26] Info: Found the 'unhide-tcp' command: /usr/sbin/unhide-tcp
[00:49:27]  Checking for hidden ports                      [ None found ]
[00:49:28]
[00:49:28] Performing checks on the network interfaces
[00:49:28] Info: Starting test name 'promisc'
[00:49:28]  Checking for promiscuous interfaces            [ None found ]
[00:49:28]
[00:49:28] Info: Test 'packet_cap_apps' disabled at users request.
[00:49:28]
[00:49:28] Info: Starting test name 'local_host'
[00:49:29] Checking the local host...
[00:49:29]
[00:49:29] Info: Starting test name 'startup_files'
[00:49:29] Performing system boot checks
[00:49:29]  Checking for local host name                    [ Found ]
[00:49:29]
[00:49:29] Info: Starting test name 'startup_malware'
[00:49:29]  Checking for system startup files              [ Found ]
[00:49:46]  Checking system startup files for malware      [ None found ]
[00:49:46]
[00:49:46] Info: Starting test name 'group_accounts'
[00:49:46] Performing group and account checks
[00:49:46]  Checking for passwd file                        [ Found ]
[00:49:46] Info: Found password file: /etc/passwd
[00:49:47]  Checking for root equivalent (UID 0) accounts  [ None found ]
[00:49:47] Info: Found shadow file: /etc/shadow
[00:49:47]  Checking for passwordless accounts              [ None found ]
[00:49:47]
[00:49:47] Info: Starting test name 'passwd_changes'
[00:49:47]  Checking for passwd file changes                [ Warning ]
[00:49:47] Warning: User 'clamav' has been added to the passwd file.
[00:49:47] Warning: User 'c-icap' has been added to the passwd file.
[00:49:47]
[00:49:47] Info: Starting test name 'group_changes'
[00:49:47]  Checking for group file changes                [ Warning ]
[00:49:47] Warning: Group 'vlock' has been added to the group file.
[00:49:47] Warning: Group 'clamav' has been added to the group file.
[00:49:47] Warning: Group 'c-icap' has been added to the group file.
[00:49:47]  Checking root account shell history files      [ None found ]
[00:49:47]
[00:49:47] Info: Starting test name 'system_configs'
[00:49:47] Performing system configuration file checks
[00:49:47]  Checking for an SSH configuration file          [ Not found ]
[00:49:48]  Checking for a running system logging daemon    [ Found ]
[00:49:48] Info: A running 'rsyslog' daemon has been found.
[00:49:48] Info: A running 'systemd-journald' daemon has been found.
[00:49:48] Info: Found an rsyslog configuration file: /etc/rsyslog.conf
[00:49:48] Info: Found a systemd configuration file: /etc/systemd/journald.conf
[00:49:48]  Checking for a system logging configuration file [ Found ]
[00:49:48]  Checking if syslog remote logging is allowed    [ Not allowed ]
[00:49:49]
[00:49:49] Info: Starting test name 'filesystem'
[00:49:49] Performing filesystem checks
[00:49:49] Info: SCAN_MODE_DEV set to 'THOROUGH'
[00:50:10]  Checking /dev for suspicious file types        [ Warning ]
[00:50:10] Warning: Suspicious file types found in /dev:
[00:50:10]          /dev/shm/pulse-shm-1345573933: data
[00:50:11]          /dev/shm/pulse-shm-218296524: data
[00:50:11]          /dev/shm/pulse-shm-519599192: data
[00:50:11]          /dev/shm/pulse-shm-927969031: data
[00:50:11]          /dev/shm/pulse-shm-735769416: data
[00:50:11]          /dev/shm/ecryptfs-ruut-Private: ASCII text
[00:50:11]          /dev/shm/pulse-shm-3336728073: data
[00:50:12]          /dev/shm/pulse-shm-2617881712: data
[00:50:12]  Checking for hidden files and directories      [ None found ]
[00:50:12]  Checking for missing log files                  [ Skipped ]
[00:50:12]  Checking for empty log files                    [ Skipped ]
[00:51:47]
[00:51:47] Info: Test 'apps' disabled at users request.
[00:51:47]
[00:51:47] System checks summary
[00:51:48] =====================
[00:51:48]
[00:51:48] File properties checks...
[00:51:48] Files checked: 148
[00:51:48] Suspect files: 10
[00:51:48]
[00:51:48] Rootkit checks...
[00:51:48] Rootkits checked : 365
[00:51:48] Possible rootkits: 0
[00:51:48]
[00:51:48] Applications checks...
[00:51:48] All checks skipped
[00:51:49]
[00:51:49] The system checks took: 10 minutes and 49 seconds
[00:51:49]
[00:51:49] Info: End date is Do 17. Mär 00:51:49 CET 2016


dennissteins 17.03.2016 01:58

CHKROOTKIT -x, und hier sind ja alle Experten:
Log nur ausschnittsweise, sonst bekomme ich wieder ärger, dass ich so viel Mist poste
Code:

Diagnostic-Code: %s; %.800s
Last-Attempt-Date:
Will-Retry-Until:
Content-Type:
errbody: I/O error
()<>@,;:\.[]"
*** Return To Sender: msg="%s", depth=%d, e=%p, returnq=
554 5.3.0 returntosender: infinite recursion on %s
554 5.3.0 returntosender: cannot select queue for %s
multipart/report; report-type=delivery-status;
        boundary="%s"
Postmaster notify: see transcript for details
Returned mail: see transcript for details
savemail, errormode = %c, id = %s, ExitStat = %d
  e_from=
553 5.3.5 Cannot parse Postmaster!
554 5.3.0 savemail: bogus errormode x%x
554 5.3.5 savemail: unknown state %d
554 savemail: cannot save rejected email anywhere
relayed to non-DSN-aware mailer
successfully delivered to mailbox
successfully delivered to mailing list
relayed (to non-DSN-aware mailer)
expanded (to multi-recipient alias)
relayed (Deliver-By trace mode)
delayed (Deliver-By notify mode)
relayed (Deliver-By notify mode)
  ----- Original message follows -----
  ----- Message header follows -----
  ----- Original message lost -----
This is a MIME-encapsulated message
    **********************************************
    **      THIS IS A WARNING MESSAGE ONLY      **
    **  YOU DO NOT NEED TO RESEND YOUR MESSAGE  **
The original message was received at %s
  ----- The following addresses had permanent fatal errors -----
  ----- The following addresses had transient non-fatal errors -----
  ----- The following addresses had successful delivery notifications -----
  ----- Transcript of session is unavailable -----
  ----- Transcript of session follows -----
Content-Type: message/delivery-status
Original-Recipient: %.100s;%.700s
returntosender: q_finalrcpt is NULL
  ----- Message body suppressed -----
  ----- No message was collected -----
AUTH: sasl_encode error=%d
sfsasl.c
AUTH: sasl_decode error=%d
sasl
read W BLOCK
read R BLOCK
generic SSL error
write X BLOCK
syscall error
STARTTLS: write error=timeout
STARTTLS: read error=timeout
SM_ASSERT(con != NULL) failed
@sasl_read failure: outbuf == NULL but outlen != 0
STARTTLS=%s, info: fds=%d/%d, err=%d
STARTTLS=%s, error: fd %d/%d too large
STARTTLS: write error=%s (%d), errno=%d, get_error=%s, retry=%d, ssl_err=%d
STARTTLS: write error=%s (%d), errno=%d, retry=%d, ssl_err=%d
STARTTLS: read error=%s (%d), errno=%d, get_error=%s, retry=%d, ssl_err=%d
STARTTLS: read error=%s (%d), retry=%d, ssl_err=%d
sm_resolve.c
dns_lookup(%s, %d, %s)
dns_lookup: domain=%s, length=%d, default_size=%d, max=%d, status=response too long
dns_lookup: domain=%s, length=%d, default_size=%d, max=%d, status=response longer than default size, resizing
dns_lookup(%s, %d, %s) --> %d
ERROR: DNS RDLENGTH=%d > data len=%d
ERROR: DNS TXT record size=%d <= text len=%d
501 5.5.2 Syntax error in parameters scanning "%s"
AUTH error: listmech=%d, num=%d
AUTH: available mech=%s, allowed mech=%s
501 5.5.2 SIZE requires a value
552 5.2.3 Message size exceeds maximum value
552 5.2.3 Message size invalid
501 5.5.2 BODY requires a value
501 5.5.4 Unknown BODY type %s
504 5.7.0 Sorry, ENVID not supported, we do not allow DSN
501 5.5.2 ENVID requires a value
501 5.5.4 Syntax error in ENVID parameter value
501 5.5.0 Duplicate ENVID parameter
504 5.7.0 Sorry, RET not supported, we do not allow DSN
501 5.5.2 RET requires a value
501 5.5.0 Duplicate RET parameter
501 5.5.2 Bad argument "%s" to RET
501 5.5.2 AUTH= requires a value
501 5.5.0 Duplicate AUTH parameter
501 5.5.4 Syntax error in AUTH parameter value
auth="%.100s" not trusted user="%.100s"
501 5.5.2 BY= requires a value
501 5.5.4 mode R requires BY time > 0
555 5.5.2 time %ld less than %ld
501 5.5.2 illegal by-mode '%c'
501 5.5.2 illegal by-trace '%c'
555 5.5.4 %s parameter unrecognized
504 5.7.0 Sorry, NOTIFY not supported, we do not allow DSN
501 5.5.2 NOTIFY requires a value
501 5.5.4 Bad argument "%s"  to NOTIFY
504 5.7.0 Sorry, ORCPT not supported, we do not allow DSN
501 5.5.2 ORCPT requires a value
501 5.5.0 Duplicate ORCPT parameter
501 5.5.4 Syntax error in ORCPT parameter value
%s: possible SMTP attack: command=%.40s, count=%u
502 5.3.0 Sendmail %s -- HELP not implemented
214-2.0.0 This is Sendmail version %s
504 5.3.0 HELP topic "%.10s" unknown
%s too old (require version %d)
fcntl(inchfd, F_GETFL) failed: %s
fcntl(outchfd, F_GETFL) failed: %s
set automode for I (%d)/O (%d) in SMTP server
srvfeatures: unknown feature %s
450 4.3.0 Please try again later.
ERROR: srv_features=tempfail, relay=%.100s, access temporarily disabled
AUTH error: sasl_server_new failed=%d
Milter: initialization failed, rejecting commands
Milter: initialization failed, temp failing commands
Milter: initialization failed, closing connection
SM_ASSERT(q != NULL || OpMode == MD_SMTP) failed
Milter: connect: host=%s, addr=%s, rejecting commands
Milter: connect: host=%s, addr=%s, temp failing commands
Milter: connect: host=%s, addr=%s, shutdown
rejecting commands from %s [%s] due to pre-greeting traffic after %d seconds
421 4.4.1 %s Lost input channel from %s
lost input channel from %s to %s after %s
421 4.7.0 %s Command too long, possible attack %s
%s: SMTP violation, input too long: %lu
421 4.7.0 %s Rejecting open proxy %s
%s: probable open proxy: command=%.40s
unauthorized PIPELINING, sleeping, relay=%.100s
501 5.5.4 cannot decode AUTH parameter %s
AUTH=server, relay=%s, authid=%.128s, mech=%.16s, bits=%d
454 4.5.4 Internal error: unable to encode64
AUTH encode64 error [%d for "%s"], relay=%.100s
AUTH continue: msg='%s' len=%u
535 5.7.0 authentication failed
AUTH failure (%s): %s (%d) %s, relay=%.100s
%s: %s: delaying %s: load average: %d
delaying=%s, load average=%d >= %d
421 4.7.0 %s Too many bad commands; closing connection
503 5.5.0 Already Authenticated
503 5.5.0 AUTH not permitted during a mail transaction
454 4.3.0 Please try again later
SMTP AUTH command (%.100s) from %s tempfailed (due to previous checks)
501 5.5.2 AUTH mechanism must be specified
504 5.3.3 AUTH mechanism %.32s not available
501 5.5.4 cannot BASE64 decode '%s'
AUTH decode64 error [%d for "%s"], relay=%.100s
454 4.5.4 Temporary authentication failure
AUTH encode64 error [%d for "%s"]
501 5.5.2 Syntax error (no parameters allowed)
454 4.3.3 TLS not available after start
503 5.5.0 TLS not permitted during a mail transaction
454 4.7.0 Please try again later
SMTP STARTTLS command (%.100s) from %s tempfailed (due to previous checks)
454 4.3.3 TLS not available: error generating SSL handle
454 4.3.3 TLS not available: error set fd
STARTTLS=server, error: accept failed=%d, reason=%s, SSL_error=%d, errno=%d, retry=%d, relay=%.100s
503 5.7.0 Authentication required.
454 4.3.3 TLS not available: can't switch to encrypted layer
STARTTLS: can't switch to encrypted layer
501 %s requires domain address
invalid domain name (too long) from %s
invalid domain name (%s) from %.100s
CLEAR_STATE: e_id=%s, EF_LOGSENDER=%d, LogLevel=%d
Milter: helo=%s, reject=Command rejected
451 4.3.2 Please try again later
Milter: helo=%s, reject=421 4.7.0 %s closing connection
503 5.0.0 Polite people say HELO first
503 5.5.0 Sender already specified
530 5.7.0 Authentication required
SMTP MAIL command (%.100s) from %s tempfailed (due to previous checks)
552 5.2.3 Message size exceeds fixed maximum message size (%ld)
Milter: %s=%s, reject=421, errormode=4
Milter: %s=%s, reject=550 5.7.1 Command rejected
421 4.7.0 %s Too many bad recipients; closing connection
%s: Possible SMTP RCPT flood, shutting down connection.
%s: Possible SMTP RCPT flood, throttling.
503 5.0.0 Need MAIL before RCPT
503 5.0.0 Need RCPT (recipient)
Milter: cmd=data, reject=550 5.7.1 Command rejected
Milter: cmd=data, reject=421 4.7.0 %s closing connection
Milter: data, reject=554 5.7.1 Command rejected
Milter: data, reject=421 4.7.0 %s closing connection
250 2.0.0 %s Message accepted for delivery
abortmessage: e_id=%s, EF_LOGSENDER=%d, LogLevel=%d
550 5.7.1 Please try again later
SMTP %s command (%.100s) from %s tempfailed (due to previous checks)
252 2.5.2 Cannot VRFY user; try RCPT to attempt delivery (or try finger)
502 5.7.0 Sorry, we do not allow this operation
503 5.0.0 I demand that you introduce yourself first
SMTP ETRN command (%.100s) from %s tempfailed (due to previous checks)
250 2.0.0 Queuing for queue group %s started
250 2.0.0 Queuing for node %s started
221 2.0.0 %s closing connection
QUIT: e_id=%s, EF_LOGSENDER=%d, LogLevel=%d
%s did not issue MAIL/EXPN/VRFY/ETRN during connection to %s
500 5.5.1 Command unrecognized: "%s"
502 5.5.1 Command not implemented: "%s"
500 5.5.0 smtp: unknown code %d
@(#)$Debug: leak_smtp - trace memory leaks during SMTP processing $
AUTH warning: no mechanisms
size
srvrsmtp.c
8bitmime
envid
trust_auth
auth="%.100s" trusted
501 5.5.2 BY=%s out of range
501 5.5.2 BY= missing ';'
orcpt
%s: got arg %s="%s"
501 5.5.4 Too many parameters
=<>")
#vers       
214-2.0.0 %s
214 2.0.0 End of HELP info
pleased to meet you
accepting invalid domain name
 (will queue)
VRFY
check_vrfy
check_expn
smtp() heap group #%d
server %s startup
srv_features
temp
greet_pause
%s not accepting messages
%s %%.*s ESMTP%%s
%s-%%.*s ESMTP%%s
server cmd read
server %s cmd read
AUTH
501 5.0.0 AUTH aborted
235 2.0.0 OK Authenticated
AUTH auth_ssf: %u
503 5.3.3 SASL TLS failed
334 %s
<<< %s
<-- %s
%s %s: %.80s
550 5.0.0 %s
503 5.3.3 AUTH not available
503 5.5.0 TLS not available
220 2.0.0 Ready to start TLS
tls_client
server EHLO
server HELO
HELO/EHLO
501 Invalid domain name
[].-_#:
Milter: helo=%s, reject=%s
421-
250 %s Hello %s, %s
250-%s Hello %s, %s
250 ENHANCEDSTATUSCODES
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-EXPN
250-VERB
250-SIZE %ld
250-SIZE
250-DSN
250-ETRN
250-AUTH %s
250-STARTTLS
250-DELIVERBY %ld
250 HELP
250-DELIVERBY
server MAIL
%s didn't use HELO protocol
{nbadrcpts}
{mail_mailer}
{mail_host}
{mail_addr}
%s owned process doing -bs
{mail_from}
check_mail
421 4.3.0 closing connection
Milter: %s=%s, reject=%s
Milter: %s=%s, discard
250 2.1.0 Sender ok
{rcpt_mailer}
{rcpt_host}
{rcpt_addr}
server RCPT
452 4.5.3 Too many recipients
501 5.0.0 Missing recipient
check_rcpt
550 5.1.1 Addressee unknown
250 2.1.5 Recipient ok%s
server DATA
503 5.0.0 Need MAIL command
check_data
Milter: cmd=data, reject=%s
Milter: cmd=data, discard
check_eom
Milter: data, reject=%s
Milter: data, discard
Milter accept: message
451 4.0.0 Test failure
250 2.0.0 Reset state
%s: %s [rejected]
501 5.5.2 Argument required
554 5.5.2 Nothing to %s
2.1.5
%s <%s@%s>
%s <%s>
500 5.5.2 Parameter required
check_etrn
%s: ETRN %s
459 4.5.4 Queue %s unknown
500 5.5.0 ETRN out of memory
NOOP
250 2.0.0 OK
aborted by sender
502 5.7.0 Verbose unavailable
250 2.0.0 Verbose mode
Bogus
"%s" command from %s (%.100s)
Sending "%s" to Milter
Unimpl
POST
USER
leak_smtp
noop
ehlo
saml
soml
showq
STAB: %s %d
(hfunc=%d)
type %d val %lx %lx %lx %lx
entered
stab: unknown symbol type %d
size of stab entry: %d
stab.c
stabapply: trying %d/%s
$%s%s
stab: total=%d (%d)
stab: type[%2d]=%2d (%d)
poststats: %s: %s
SSL_connect
SSL_accept
undefined
STARTTLS: %s:%s
STARTTLS: SSL3 alert %s:%s:%s
STARTTLS: %s:failed in %s
STARTTLS: %s:error in %s
Server
Client
STARTTLS: %s%s missing
x509
UNKNOWN
tls.c
BadCertificateUnknown
cn_subject
BadCertificateTooLong
BadCertificateContainsNUL
cn_issuer
{cert_md5}
STARTTLS=%s: %lu:%s:%s:%d:%s
STARTTLS=%s, init=%d
SM_ASSERT(ctx != NULL) failed
STARTTLS: info_callback where=0x%x, ret=%d
STARTTLS=server, tmp_rsa_key: RSA_generate_key failed!
STARTTLS=server, tmp_rsa_key: new temp RSA key
STARTTLS=%s: file %s unsafe: %s
STARTTLS: internal error: tls_verify_cb: ssl == NULL
STARTTLS: %s cert verify: depth=%d %s, state=%d, reason=%s
STARTTLS=%s, get_verify: %ld get_peer: 0x%lx
STARTTLS=%s, relay=%.100s, field=%s, status=failed to extract CN
STARTTLS=%s, relay=%.100s, field=%s, status=CN too long
STARTTLS=%s, relay=%.100s, field=%s, status=CN contains NUL
SM_ASSERT((n * 3) + 2 < sizeof(md5h)) failed
STARTTLS=%s, relay=%.100s, version=%.16s, verify=%.16s, cipher=%.64s, bits=%.6s/%.6s
STARTTLS=%s, cert-subject=%.256s, cert-issuer=%.256s, verifymsg=%s
STARTTLS=%s, error: illegal value '%s' for DHParam
STARTTLS=%s, error: SSL_CTX_new(SSLv23_%s_method()) failed
STARTTLS=%s, error: PEM_read_bio_X509_CRL(%s)=failed
STARTTLS=%s, error: BIO_new=failed
STARTTLS=%s, error: RSA_generate_key failed
STARTTLS=%s, error: SSL_CTX_use_PrivateKey_file(%s) failed
STARTTLS=%s, error: SSL_CTX_use_certificate_file(%s) failed
STARTTLS=%s, error: SSL_CTX_check_private_key failed(%s): %d
STARTTLS=%s, error: SSL_CTX_check_private_key 2 failed: %d
STARTTLS=%s, error: cannot read DH parameters(%s): %s
STARTTLS=%s, error: BIO_new_file(%s) failed
inittls: Generating %d bit DH parameters
inittls: Using precomputed 512 bit DH parameters
STARTTLS=%s, error: cannot read or set DH parameters(%s): %s
STARTTLS=%s, Diffie-Hellman init, key=%d bit (%c)
STARTTLS=%s, error: load verify locs %s, %s failed: %d
STARTTLS=%s, error: SSL_CTX_set_cipher_list(%s) failed, list ignored
STARTTLS=%s, inittls: ctx == NULL
STARTTLS=%s, SSL_shutdown failed: %d
STARTTLS=%s, SSL_shutdown not done
0123456789ABCDEF
Maximum number of UDB entries exceeded
udbmatch: no match on %s (%d) via db
udbexpand: trying %s (%d) via db
udbexpand: no match on %s (%d)
udb.c
db_open(%s): %s
db_open(%s): %s
_udbx_init: db_open(%s)
Unknown UDB spec %s
REMOTE: addr %s, timeo %d
FETCH: file %s
FORWARD: host %s
HESIOD
UNKNOWN
_udbx_init: db->close(%s)
udbmatch(%s, %s)
udbmatch ==> %s
:maildrop
:default:mailname
udbexpand(%s)
udbexpand: match %.*s: %.*s
expanded to %s
expand %.100s => %s
udbexpand: QS_EXPANDED
:mailsender
udb_map_lookup(%s, %s)
_udbx_close: db->close(%s)
usersmtp.c
AUTH username '%s'
AUTH authid '%s'
8BIT-OK
authinfo
getauth %s=%s
enhancedstatuscodes
pipelining
deliverby
AUTH flags=%lx, mechs=%s
<No Realms>
<No Realm>
>>> %s
smtpmessage: NULL mci_out
smtpquit:1
client QUIT
STARTTLS dialogue
AUTH dialogue
reply
reply:1
reply:2
%s...
reply(%.100s) during %s
... while talking to %s:
050 %s
5.1.3
lmtp
LOGIN
DIGEST-MD5
AUTH %s =
encode64 for AUTH failed
AUTH %s %s
AUTH FAIL=%s (%d)
HDRS
FULL
smtpmailfrom: CurHost=%s
 SIZE=%ld
 BODY=%s
%s does not support 8BITMIME
 ENVID=%s
 RET=%s
 AUTH=%s
 BY=%ld;%c%s
MAIL From:<%s>%s
MAIL From:<@%s%c%s>%s
client MAIL
 NOTIFY=
 ORCPT=%s
RCPT To:<%s>%s
client RCPT
client RSET
client LHLO
client EHLO
client HELO
smtpinit
client greeting
LHLO %s
EHLO %s
HELO %s
553 5.3.5 system config error
client DATA 354
%05d >>> .
>>> .
client DATA status
client probe
user id
authentication id
password
realm
mechlist
error: safesasl(%s) failed: %s
AUTH=client, relay=%.64s [%.16s], authinfo %sfailed
AUTH=client, error: can't open %s: %s
AUTH=client, error: can't read %s from %s
str_union: stringlen1=%d, stringlen2=%d, sum=%d, status=overflow
AUTH=client, realm=%s, available realms=%s
AUTH=client, realm=%s not in list=%s
smtpquit: mailer%s%s exited with exit value %d
421 4.4.1 Connection reset by %s
451 4.4.1 reply: read error from %s
%.100s: SMTP RCPT protocol error: %s
%.100s: SMTP DATA-3 protocol error: %s
AUTH=client, available mechanisms do not fulfill requirements
%.100s: SMTP MAIL protocol error: %s
451 4.4.0 smtpinit: state CLOSED (was %d)
553 5.3.5 %s config error: mail loops back to me (MX problem?)
%.100s: SMTP DATA-1 protocol error: %s
%.100s: SMTP DATA-2 protocol error: %s
451 4.4.1 timeout writing message to %s
util.c
SM_REQUIRE(sz >= 0) failed
SM_ASSERT(l + 1 > l) failed
unable to write pid to %s: %s
started as: %s
{deliveryMode}
%s<null>%s
=~&?
%s$%c
%sM-
 %o
 %#x
        %08lx=
%05d >>> 
unlink %s
%s: unlink-fail %d
SM_REQUIRE(np != NULL) failed
SM_REQUIRE(n > 0) failed
tTyY
SM_REQUIRE(siz > 0) failed
%05d <<< [TIMEOUT]
%05d <<< [EOF]
%05d <<< %s
%3d:
CANNOT STAT (%s)
CLOSED
fl=0x%x,
mode=%o:
SOCK
%s/%d
CHR:
BLK:
FIFO:
DIR:
LNK:
size=%llu
%s: changed fds:
%s: cannot fork
%s: cannot dup2 for stdout
%s: cannot dup2 for stderr
%s: lockfp does not have a fd
prog_open: cannot chroot(%s)
prog_open: cannot chdir(/)
prog_open: setgid(%ld) failed
prog_open: setuid(%ld) failed
/tmp
%s: cannot exec
[UNKNOWN]
!cleanstrcpy: length == 0
!#$%&'*+-./^_`{|}~
control socket
proc_list_probe: lost pid %d
proc_list_probe
(unknown)
%s%d %s%s
ANSI
unable to write pid to %s: file in use by another process
SM_REQUIRE(buf != NULL) failed
timeout waiting for input from %.100s during %s
dev=%d/%d, ino=%llu, nlink=%d, u/gid=%d/%d,
checkfdopen(%d): %s not open as expected!
%s: cannot create pipe for stdout
Warning: prog_open: program %s unsafe: %s
POSSIBLE ATTACK from %.100s: newline in string "%s"
proc_list_probe: found %d children, expected %d
SM_ASSERT(ProcListSize < INT_MAX - PROC_LIST_SEG) failed
SM_ASSERT(CurChildren < INT_MAX) failed
@(#)$Debug: ANSI - enable reverse video in debug output $
World
Group
        [dir %s]
        [dir %s] mode %lo
FATAL
WARNING
        [dir %s] %s

....
....
....
/usr/include/./X11/bitmaps/boxes
/usr/include/./X11/bitmaps/mailemptymsk
/usr/include/./X11/bitmaps/xsnow
/usr/include/./X11/bitmaps/FlipHoriz
/usr/include/./X11/bitmaps/star
/usr/include/./X11/bitmaps/flipped_gray
/usr/include/./X11/bitmaps/escherknot
/usr/include/./X11/bitmaps/flagup
/usr/include/./X11/bitmaps/terminal
/usr/include/./X11/bitmaps/Excl
/usr/include/./X11/bitmaps/vlines3
/usr/include/./X11/bitmaps/menu12
/usr/include/./X11/bitmaps/dimple1
/usr/include/./X11/bitmaps/dot
/usr/include/./X11/bitmaps/menu8
/usr/include/./X11/bitmaps/dimple3
/usr/include/./X11/bitmaps/mailempty
/usr/include/./X11/bitmaps/xlogo64
/usr/include/./X11/bitmaps/mensetmanus
/usr/include/./X11/bitmaps/letters
/usr/include/./X11/bitmaps/Dashes
/usr/include/./X11/bitmaps/keyboard16
/usr/include/./X11/bitmaps/hlines3
/usr/include/./X11/bitmaps/starMask
/usr/include/./X11/bitmaps/menu6
/usr/include/./X11/bitmaps/tie_fighter
/usr/include/./X11/bitmaps/right_ptr
/usr/include/./X11/bitmaps/RotateLeft
/usr/include/./X11/bitmaps/xlogo32
/usr/include/./X11/bitmaps/mailfullmsk
/usr/include/./X11/bitmaps/2x2
/usr/include/./X11/bitmaps/Left
/usr/include/./X11/bitmaps/box6
/usr/include/./X11/bitmaps/grid4
/usr/include/./X11/bitmaps/hlines2
/usr/include/./X11/bitmaps/gray
/usr/include/./X11/bitmaps/weird_size
/usr/include/./X11/bitmaps/mailfull
/usr/include/./X11/bitmaps/Fold
/usr/include/./X11/bitmaps/menu16
/usr/include/./X11/bitmaps/root_weave
/usr/include/./X11/bitmaps/sipb
/usr/include/./X11/bitmaps/black
/usr/include/./X11/bitmaps/ldblarrow
/usr/include/./X11/bitmaps/grid8
/usr/include/./X11/bitmaps/black6
/usr/include/./X11/bitmaps/left_ptrmsk
/usr/include/./X11/bitmaps/vlines2
/usr/include/./X11/bitmaps/gray3
/usr/include/./X11/bitmaps/wide_weave
/usr/include/./X11/bitmaps/right_ptrmsk
/usr/include/./X11/bitmaps/xlogo11
/usr/include/./X11/bitmaps/Stipple
/usr/include/./X11/bitmaps/opendot
/usr/include/./X11/bitmaps/FlipVert
/usr/include/./X11/bitmaps/rdblarrow
/usr/include/./X11/bitmaps/icon
/usr/include/./X11/bitmaps/noletters
/usr/include/./X11/bitmaps/dropbar7
/usr/include/./X11/bitmaps/grid16
/usr/include/./X11/bitmaps/gray1
/usr/include/./X11/bitmaps/cntr_ptrmsk
/usr/include/./X11/bitmaps/grid2
/usr/include/./X11/bitmaps/1x1
/usr/include/./X11/bitmaps/left_ptr
/usr/include/./X11/bitmaps/menu10
/usr/include/./X11/bitmaps/Right
/usr/include/./X11/bitmaps/wingdogs
/usr/include/./X11/bitmaps/woman
/usr/include/./X11/bitmaps/dropbar8
/usr/include/./X11/bitmaps/stipple
/usr/include/./X11/bitmaps/xlogo16
/usr/include/./X11/bitmaps/opendotMask
/usr/include/./X11/bitmaps/light_gray
/usr/include/./X11/bitmaps/Up
/usr/include/./X11/bitmaps/calculator
/usr/include/./X11/bitmaps/scales
/usr/include/./X11/bitmaps/target
/usr/include/./X11/bitmaps/RotateRight
/usr/include/./X11/bitmaps/cross_weave
/usr/include/./tommath.h
/usr/include/./memory.h
/usr/include/./pwd.h
/usr/include/./shadow.h
/usr/include/./elf.h
/usr/include/./netpacket
/usr/include/./netpacket/packet.h
/usr/include/./wchar.h
/usr/include/./ustat.h
/usr/include/./geany
/usr/include/./geany/scintilla
/usr/include/./geany/scintilla/ScintillaWidget.h
/usr/include/./geany/scintilla/SciLexer.h
/usr/include/./geany/scintilla/Scintilla.iface
/usr/include/./geany/scintilla/Scintilla.h
/usr/include/./geany/navqueue.h
/usr/include/./geany/stash.h
/usr/include/./geany/app.h
/usr/include/./geany/symbols.h
/usr/include/./geany/plugindata.h
/usr/include/./geany/encodings.h
/usr/include/./geany/main.h
/usr/include/./geany/pluginutils.h
/usr/include/./geany/project.h
/usr/include/./geany/build.h
/usr/include/./geany/ui_utils.h
/usr/include/./geany/editor.h
/usr/include/./geany/geanyfunctions.h
/usr/include/./geany/document.h
/usr/include/./geany/highlighting.h
/usr/include/./geany/geany.h
/usr/include/./geany/keybindings.h
/usr/include/./geany/dialogs.h
/usr/include/./geany/gtkcompat.h
/usr/include/./geany/utils.h
/usr/include/./geany/support.h
/usr/include/./geany/prefs.h
/usr/include/./geany/geanyplugin.h
/usr/include/./geany/sciwrappers.h
/usr/include/./geany/spawn.h
/usr/include/./geany/templates.h
/usr/include/./geany/search.h
/usr/include/./geany/filetypes.h
/usr/include/./geany/msgwindow.h
/usr/include/./geany/toolbar.h
/usr/include/./geany/tagmanager
/usr/include/./geany/tagmanager/tm_source_file.h
/usr/include/./geany/tagmanager/tm_workspace.h
/usr/include/./geany/tagmanager/tm_tag.h
/usr/include/./geany/tagmanager/tm_tagmanager.h
/usr/include/./netdb.h
/usr/include/./ctype.h
/usr/include/./glob.h
/usr/include/./turbojpeg.h
/usr/include/./envz.h
/usr/include/./features.h
/usr/include/./stropts.h
/usr/include/./ne_nemesisI_int.h
/usr/include/./scsi
/usr/include/./scsi/scsi_ioctl.h
/usr/include/./scsi/scsi.h
/usr/include/./scsi/cxlflash_ioctl.h
/usr/include/./scsi/scsi_netlink_fc.h
/usr/include/./scsi/scsi_netlink.h
/usr/include/./scsi/scsi_bsg_fc.h
/usr/include/./scsi/fc
/usr/include/./scsi/fc/fc_ns.h
/usr/include/./scsi/fc/fc_fs.h
/usr/include/./scsi/fc/fc_els.h
/usr/include/./scsi/fc/fc_gs.h
/usr/include/./scsi/sg.h
/usr/include/./spawn.h
/usr/include/./ftw.h
/usr/include/./monetary.h
/usr/include/./byteswap.h
/usr/include/./obstack.h
/usr/include/./regex.h
/usr/include/./termios.h
/usr/include/./hdf5
/usr/include/./hdf5/serial
/usr/include/./hdf5/serial/H5Cpublic.h
/usr/include/./hdf5/serial/h5f.mod
/usr/include/./hdf5/serial/H5Epubgen.h
/usr/include/./hdf5/serial/h5e.mod
/usr/include/./hdf5/serial/H5Ipublic.h
/usr/include/./hdf5/serial/h5_dble_interface.mod
/usr/include/./hdf5/serial/h5i.mod
/usr/include/./hdf5/serial/H5overflow.h
/usr/include/./hdf5/serial/H5File.h
/usr/include/./hdf5/serial/H5Epublic.h
/usr/include/./hdf5/serial/H5PacketTable.h
/usr/include/./hdf5/serial/h5e_provisional.mod
/usr/include/./hdf5/serial/h5lt.mod
/usr/include/./hdf5/serial/hdf5_hl.h
/usr/include/./hdf5/serial/H5FDstdio.h
/usr/include/./hdf5/serial/h5l.mod
/usr/include/./hdf5/serial/H5FDcore.h
/usr/include/./hdf5/serial/H5StrType.h
/usr/include/./hdf5/serial/H5DxferProp.h
/usr/include/./hdf5/serial/H5Library.h
/usr/include/./hdf5/serial/H5FDmpi.h
/usr/include/./hdf5/serial/h5d.mod
/usr/include/./hdf5/serial/H5f90i_gen.h
/usr/include/./hdf5/serial/h5o.mod
/usr/include/./hdf5/serial/H5Zpublic.h
/usr/include/./hdf5/serial/h5f_provisional.mod
/usr/include/./hdf5/serial/h5l_provisional.mod
/usr/include/./hdf5/serial/H5Dpublic.h
/usr/include/./hdf5/serial/H5IdComponent.h
/usr/include/./hdf5/serial/H5Group.h
/usr/include/./hdf5/serial/h5fortran_types.mod
/usr/include/./hdf5/serial/H5FcreatProp.h
/usr/include/./hdf5/serial/H5EnumType.h
/usr/include/./hdf5/serial/H5IMpublic.h
/usr/include/./hdf5/serial/H5PTpublic.h
/usr/include/./hdf5/serial/H5Attribute.h
/usr/include/./hdf5/serial/H5Object.h
/usr/include/./hdf5/serial/H5DataSpace.h
/usr/include/./hdf5/serial/H5Cpp.h
/usr/include/./hdf5/serial/H5pubconf.h
/usr/include/./hdf5/serial/H5Lpublic.h
/usr/include/./hdf5/serial/H5FDdirect.h
/usr/include/./hdf5/serial/H5ACpublic.h
/usr/include/./hdf5/serial/H5PropList.h
/usr/include/./hdf5/serial/h5p_provisional.mod
/usr/include/./hdf5/serial/h5d_provisional.mod
/usr/include/./hdf5/serial/h5t.mod
/usr/include/./hdf5/serial/H5public.h
/usr/include/./hdf5/serial/H5CompType.h
/usr/include/./hdf5/serial/H5AtomType.h
/usr/include/./hdf5/serial/h5o_provisional.mod
/usr/include/./hdf5/serial/H5Fpublic.h
/usr/include/./hdf5/serial/H5MMpublic.h
/usr/include/./hdf5/serial/hdf5.h
/usr/include/./hdf5/serial/H5FDmulti.h
/usr/include/./hdf5/serial/H5FaccProp.h
/usr/include/./hdf5/serial/H5DOpublic.h
/usr/include/./hdf5/serial/H5Opublic.h
/usr/include/./hdf5/serial/h5im.mod
/usr/include/./hdf5/serial/H5PLextern.h
/usr/include/./hdf5/serial/H5api_adpt.h
/usr/include/./hdf5/serial/H5Apublic.h
/usr/include/./hdf5/serial/H5CommonFG.h
/usr/include/./hdf5/serial/H5IntType.h
/usr/include/./hdf5/serial/H5FDfamily.h
/usr/include/./hdf5/serial/H5Rpublic.h
/usr/include/./hdf5/serial/hdf5.mod
/usr/include/./hdf5/serial/H5FDsec2.h
/usr/include/./hdf5/serial/H5PLpublic.h
/usr/include/./hdf5/serial/H5DataType.h
/usr/include/./hdf5/serial/H5PredType.h
/usr/include/./hdf5/serial/h5z.mod
/usr/include/./hdf5/serial/H5FDlog.h
/usr/include/./hdf5/serial/h5global.mod
/usr/include/./hdf5/serial/h5r_provisional.mod
/usr/include/./hdf5/serial/H5ArrayType.h
/usr/include/./hdf5/serial/H5VarLenType.h
/usr/include/./hdf5/serial/H5TBpublic.h
/usr/include/./hdf5/serial/H5CppDoc.h
/usr/include/./hdf5/serial/H5Gpublic.h
/usr/include/./hdf5/serial/H5Location.h
/usr/include/./hdf5/serial/h5lib.mod
/usr/include/./hdf5/serial/H5FloatType.h
/usr/include/./hdf5/serial/H5FDmpio.h
/usr/include/./hdf5/serial/h5lib_provisional.mod
/usr/include/./hdf5/serial/H5Ppublic.h
/usr/include/./hdf5/serial/H5DSpublic.h
/usr/include/./hdf5/serial/H5version.h
/usr/include/./hdf5/serial/H5LTpublic.h
/usr/include/./hdf5/serial/H5Classes.h
/usr/include/./hdf5/serial/h5tb.mod
/usr/include/./hdf5/serial/H5Tpublic.h
/usr/include/./hdf5/serial/h5t_provisional.mod
/usr/include/./hdf5/serial/H5DataSet.h
/usr/include/./hdf5/serial/h5a_provisional.mod
/usr/include/./hdf5/serial/h5ds.mod
/usr/include/./hdf5/serial/h5s.mod
/usr/include/./hdf5/serial/H5DcreatProp.h
/usr/include/./hdf5/serial/h5p.mod
/usr/include/./hdf5/serial/h5g.mod
/usr/include/./hdf5/serial/H5Spublic.h
/usr/include/./hdf5/serial/H5AbstractDs.h
/usr/include/./hdf5/serial/H5f90i.h
/usr/include/./hdf5/serial/H5Exception.h
/usr/include/./hdf5/serial/h5r.mod
/usr/include/./hdf5/serial/h5a.mod
/usr/include/./hdf5/serial/H5FDpublic.h
/usr/include/./hdf5/serial/H5Include.h
/usr/include/./limits.h
/usr/include/./grp.h
/usr/include/./signal.h
/usr/include/./sudo_plugin.h
/usr/include/./mqueue.h
/usr/include/./pthread.h
/usr/include/./wordexp.h
/usr/include/./nl_types.h
/usr/include/./termio.h
/usr/include/./complex.h
/usr/include/./reglib
/usr/include/./reglib/reglib.h
/usr/include/./reglib/nl80211.h
/usr/include/./reglib/regdb.h
/usr/include/./netcdf_meta.h
/usr/include/./inttypes.h
/usr/include/./assuan.h
/usr/include/./link.h
/usr/include/./xlocale.h
/usr/include/./search.h
/usr/include/./exodusII.h
/usr/include/./strings.h
/usr/include/./nss.h
/usr/include/./iconv.h
/usr/include/./wctype.h
/usr/include/./gnu-versions.h
/usr/include/./tgmath.h
/usr/include/./gnumake.h
/usr/include/./netax25
/usr/include/./netax25/ax25.h
/usr/include/./sched.h
/usr/include/./setjmp.h
/usr/include/./x86_64-linux-gnu
/usr/include/./x86_64-linux-gnu/bits
/usr/include/./x86_64-linux-gnu/bits/select2.h
/usr/include/./x86_64-linux-gnu/bits/dirent.h
/usr/include/./x86_64-linux-gnu/bits/sigset.h
/usr/include/./x86_64-linux-gnu/bits/msq.h
/usr/include/./x86_64-linux-gnu/bits/statfs.h
/usr/include/./x86_64-linux-gnu/bits/libc-lock.h
/usr/include/./x86_64-linux-gnu/bits/string.h
/usr/include/./x86_64-linux-gnu/bits/uio.h
/usr/include/./x86_64-linux-gnu/bits/waitstatus.h
/usr/include/./x86_64-linux-gnu/bits/statvfs.h
/usr/include/./x86_64-linux-gnu/bits/timex.h
/usr/include/./x86_64-linux-gnu/bits/ioctls.h
/usr/include/./x86_64-linux-gnu/bits/syslog.h
/usr/include/./x86_64-linux-gnu/bits/xopen_lim.h
/usr/include/./x86_64-linux-gnu/bits/poll.h
/usr/include/./x86_64-linux-gnu/bits/confname.h
/usr/include/./x86_64-linux-gnu/bits/fenv.h
/usr/include/./x86_64-linux-gnu/bits/auxv.h
/usr/include/./x86_64-linux-gnu/bits/stdlib-bsearch.h
/usr/include/./x86_64-linux-gnu/bits/sockaddr.h
/usr/include/./x86_64-linux-gnu/bits/select.h
/usr/include/./x86_64-linux-gnu/bits/wordsize.h
/usr/include/./x86_64-linux-gnu/bits/error.h
/usr/include/./x86_64-linux-gnu/bits/huge_val.h
/usr/include/./x86_64-linux-gnu/bits/wchar2.h
/usr/include/./x86_64-linux-gnu/bits/sys_errlist.h
/usr/include/./x86_64-linux-gnu/bits/syslog-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/socket2.h
/usr/include/./x86_64-linux-gnu/bits/in.h
/usr/include/./x86_64-linux-gnu/bits/mathinline.h
/usr/include/./x86_64-linux-gnu/bits/dlfcn.h
/usr/include/./x86_64-linux-gnu/bits/eventfd.h
/usr/include/./x86_64-linux-gnu/bits/stdio-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/math-finite.h
/usr/include/./x86_64-linux-gnu/bits/mman.h
/usr/include/./x86_64-linux-gnu/bits/huge_valf.h
/usr/include/./x86_64-linux-gnu/bits/mathdef.h
/usr/include/./x86_64-linux-gnu/bits/endian.h
/usr/include/./x86_64-linux-gnu/bits/param.h
/usr/include/./x86_64-linux-gnu/bits/semaphore.h
/usr/include/./x86_64-linux-gnu/bits/resource.h
/usr/include/./x86_64-linux-gnu/bits/byteswap-16.h
/usr/include/./x86_64-linux-gnu/bits/locale.h
/usr/include/./x86_64-linux-gnu/bits/signalfd.h
/usr/include/./x86_64-linux-gnu/bits/fenvinline.h
/usr/include/./x86_64-linux-gnu/bits/monetary-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/shm.h
/usr/include/./x86_64-linux-gnu/bits/siginfo.h
/usr/include/./x86_64-linux-gnu/bits/syscall.h
/usr/include/./x86_64-linux-gnu/bits/a.out.h
/usr/include/./x86_64-linux-gnu/bits/stdio-lock.h
/usr/include/./x86_64-linux-gnu/bits/inotify.h
/usr/include/./x86_64-linux-gnu/bits/utsname.h
/usr/include/./x86_64-linux-gnu/bits/posix1_lim.h
/usr/include/./x86_64-linux-gnu/bits/xtitypes.h
/usr/include/./x86_64-linux-gnu/bits/string3.h
/usr/include/./x86_64-linux-gnu/bits/stdio.h
/usr/include/./x86_64-linux-gnu/bits/socket_type.h
/usr/include/./x86_64-linux-gnu/bits/fcntl.h
/usr/include/./x86_64-linux-gnu/bits/mqueue2.h
/usr/include/./x86_64-linux-gnu/bits/sigaction.h
/usr/include/./x86_64-linux-gnu/bits/pthreadtypes.h
/usr/include/./x86_64-linux-gnu/bits/time.h
/usr/include/./x86_64-linux-gnu/bits/stdlib.h
/usr/include/./x86_64-linux-gnu/bits/syslog-path.h
/usr/include/./x86_64-linux-gnu/bits/environments.h
/usr/include/./x86_64-linux-gnu/bits/timerfd.h
/usr/include/./x86_64-linux-gnu/bits/waitflags.h
/usr/include/./x86_64-linux-gnu/bits/sigstack.h
/usr/include/./x86_64-linux-gnu/bits/mman-linux.h
/usr/include/./x86_64-linux-gnu/bits/string2.h
/usr/include/./x86_64-linux-gnu/bits/utmp.h
/usr/include/./x86_64-linux-gnu/bits/errno.h
/usr/include/./x86_64-linux-gnu/bits/wchar-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/poll2.h
/usr/include/./x86_64-linux-gnu/bits/sigcontext.h
/usr/include/./x86_64-linux-gnu/bits/cmathcalls.h
/usr/include/./x86_64-linux-gnu/bits/posix_opt.h
/usr/include/./x86_64-linux-gnu/bits/hwcap.h
/usr/include/./x86_64-linux-gnu/bits/elfclass.h
/usr/include/./x86_64-linux-gnu/bits/unistd.h
/usr/include/./x86_64-linux-gnu/bits/libio-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/wchar.h
/usr/include/./x86_64-linux-gnu/bits/ustat.h
/usr/include/./x86_64-linux-gnu/bits/netdb.h
/usr/include/./x86_64-linux-gnu/bits/ipc.h
/usr/include/./x86_64-linux-gnu/bits/stdlib-float.h
/usr/include/./x86_64-linux-gnu/bits/ioctl-types.h
/usr/include/./x86_64-linux-gnu/bits/ipctypes.h
/usr/include/./x86_64-linux-gnu/bits/stropts.h
/usr/include/./x86_64-linux-gnu/bits/posix2_lim.h
/usr/include/./x86_64-linux-gnu/bits/byteswap.h
/usr/include/./x86_64-linux-gnu/bits/termios.h
/usr/include/./x86_64-linux-gnu/bits/sigthread.h
/usr/include/./x86_64-linux-gnu/bits/sem.h
/usr/include/./x86_64-linux-gnu/bits/mqueue.h
/usr/include/./x86_64-linux-gnu/bits/sysctl.h
/usr/include/./x86_64-linux-gnu/bits/inf.h
/usr/include/./x86_64-linux-gnu/bits/huge_vall.h
/usr/include/./x86_64-linux-gnu/bits/local_lim.h
/usr/include/./x86_64-linux-gnu/bits/stdio2.h
/usr/include/./x86_64-linux-gnu/bits/stdio_lim.h
/usr/include/./x86_64-linux-gnu/bits/initspin.h
/usr/include/./x86_64-linux-gnu/bits/link.h
/usr/include/./x86_64-linux-gnu/bits/nan.h
/usr/include/./x86_64-linux-gnu/bits/epoll.h
/usr/include/./x86_64-linux-gnu/bits/types.h
/usr/include/./x86_64-linux-gnu/bits/socket.h
/usr/include/./x86_64-linux-gnu/bits/fcntl2.h
/usr/include/./x86_64-linux-gnu/bits/stat.h
/usr/include/./x86_64-linux-gnu/bits/printf-ldbl.h
/usr/include/./x86_64-linux-gnu/bits/typesizes.h
/usr/include/./x86_64-linux-gnu/bits/stab.def
/usr/include/./x86_64-linux-gnu/bits/signum.h
/usr/include/./x86_64-linux-gnu/bits/sched.h
/usr/include/./x86_64-linux-gnu/bits/mathcalls.h
/usr/include/./x86_64-linux-gnu/bits/setjmp.h
/usr/include/./x86_64-linux-gnu/bits/fcntl-linux.h
/usr/include/./x86_64-linux-gnu/bits/setjmp2.h
/usr/include/./x86_64-linux-gnu/bits/utmpx.h
/usr/include/./x86_64-linux-gnu/bits/stdlib-ldbl.h
/usr/include/./x86_64-linux-gnu/openssl
/usr/include/./x86_64-linux-gnu/openssl/opensslconf.h
/usr/include/./x86_64-linux-gnu/gnu
/usr/include/./x86_64-linux-gnu/gnu/lib-names-64.h
/usr/include/./x86_64-linux-gnu/gnu/lib-names.h
/usr/include/./x86_64-linux-gnu/gnu/libc-version.h
/usr/include/./x86_64-linux-gnu/gnu/stubs-64.h
/usr/include/./x86_64-linux-gnu/gnu/stubs.h
/usr/include/./x86_64-linux-gnu/zconf.h
/usr/include/./x86_64-linux-gnu/a.out.h
/usr/include/./x86_64-linux-gnu/sys
/usr/include/./x86_64-linux-gnu/sys/statfs.h
/usr/include/./x86_64-linux-gnu/sys/raw.h
/usr/include/./x86_64-linux-gnu/sys/sendfile.h
/usr/include/./x86_64-linux-gnu/sys/uio.h
/usr/include/./x86_64-linux-gnu/sys/timeb.h
/usr/include/./x86_64-linux-gnu/sys/ucontext.h
/usr/include/./x86_64-linux-gnu/sys/statvfs.h
/usr/include/./x86_64-linux-gnu/sys/timex.h
/usr/include/./x86_64-linux-gnu/sys/swap.h
/usr/include/./x86_64-linux-gnu/sys/syslog.h
/usr/include/./x86_64-linux-gnu/sys/io.h
/usr/include/./x86_64-linux-gnu/sys/poll.h
/usr/include/./x86_64-linux-gnu/sys/auxv.h
/usr/include/./x86_64-linux-gnu/sys/klog.h
/usr/include/./x86_64-linux-gnu/sys/select.h
/usr/include/./x86_64-linux-gnu/sys/ioctl.h
/usr/include/./x86_64-linux-gnu/sys/file.h
/usr/include/./x86_64-linux-gnu/sys/bitypes.h
/usr/include/./x86_64-linux-gnu/sys/soundcard.h
/usr/include/./x86_64-linux-gnu/sys/msg.h
/usr/include/./x86_64-linux-gnu/sys/mount.h
/usr/include/./x86_64-linux-gnu/sys/ttychars.h
/usr/include/./x86_64-linux-gnu/sys/wait.h
/usr/include/./x86_64-linux-gnu/sys/mtio.h
/usr/include/./x86_64-linux-gnu/sys/sysmacros.h
/usr/include/./x86_64-linux-gnu/sys/sysinfo.h
/usr/include/./x86_64-linux-gnu/sys/ultrasound.h
/usr/include/./x86_64-linux-gnu/sys/eventfd.h
/usr/include/./x86_64-linux-gnu/sys/mman.h
/usr/include/./x86_64-linux-gnu/sys/queue.h
/usr/include/./x86_64-linux-gnu/sys/param.h
/usr/include/./x86_64-linux-gnu/sys/kd.h
/usr/include/./x86_64-linux-gnu/sys/resource.h
/usr/include/./x86_64-linux-gnu/sys/signalfd.h
/usr/include/./x86_64-linux-gnu/sys/profil.h
/usr/include/./x86_64-linux-gnu/sys/procfs.h
/usr/include/./x86_64-linux-gnu/sys/vlimit.h
/usr/include/./x86_64-linux-gnu/sys/acct.h
/usr/include/./x86_64-linux-gnu/sys/cdefs.h
/usr/include/./x86_64-linux-gnu/sys/ptrace.h
/usr/include/./x86_64-linux-gnu/sys/shm.h
/usr/include/./x86_64-linux-gnu/sys/vt.h
/usr/include/./x86_64-linux-gnu/sys/syscall.h
/usr/include/./x86_64-linux-gnu/sys/prctl.h
/usr/include/./x86_64-linux-gnu/sys/xattr.h
/usr/include/./x86_64-linux-gnu/sys/inotify.h
/usr/include/./x86_64-linux-gnu/sys/utsname.h
/usr/include/./x86_64-linux-gnu/sys/fcntl.h
/usr/include/./x86_64-linux-gnu/sys/un.h
/usr/include/./x86_64-linux-gnu/sys/time.h
/usr/include/./x86_64-linux-gnu/sys/perm.h
/usr/include/./x86_64-linux-gnu/sys/timerfd.h
/usr/include/./x86_64-linux-gnu/sys/user.h
/usr/include/./x86_64-linux-gnu/sys/pci.h
/usr/include/./x86_64-linux-gnu/sys/errno.h
/usr/include/./x86_64-linux-gnu/sys/gmon_out.h
/usr/include/./x86_64-linux-gnu/sys/unistd.h
/usr/include/./x86_64-linux-gnu/sys/elf.h
/usr/include/./x86_64-linux-gnu/sys/reboot.h
/usr/include/./x86_64-linux-gnu/sys/ttydefaults.h
/usr/include/./x86_64-linux-gnu/sys/ustat.h
/usr/include/./x86_64-linux-gnu/sys/vfs.h
/usr/include/./x86_64-linux-gnu/sys/ipc.h
/usr/include/./x86_64-linux-gnu/sys/times.h
/usr/include/./x86_64-linux-gnu/sys/quota.h
/usr/include/./x86_64-linux-gnu/sys/debugreg.h
/usr/include/./x86_64-linux-gnu/sys/stropts.h
/usr/include/./x86_64-linux-gnu/sys/personality.h
/usr/include/./x86_64-linux-gnu/sys/termios.h
/usr/include/./x86_64-linux-gnu/sys/vm86.h
/usr/include/./x86_64-linux-gnu/sys/fanotify.h
/usr/include/./x86_64-linux-gnu/sys/signal.h
/usr/include/./x86_64-linux-gnu/sys/sem.h
/usr/include/./x86_64-linux-gnu/sys/gmon.h
/usr/include/./x86_64-linux-gnu/sys/sysctl.h
/usr/include/./x86_64-linux-gnu/sys/socketvar.h
/usr/include/./x86_64-linux-gnu/sys/epoll.h
/usr/include/./x86_64-linux-gnu/sys/types.h
/usr/include/./x86_64-linux-gnu/sys/kdaemon.h
/usr/include/./x86_64-linux-gnu/sys/socket.h
/usr/include/./x86_64-linux-gnu/sys/stat.h
/usr/include/./x86_64-linux-gnu/sys/reg.h
/usr/include/./x86_64-linux-gnu/sys/vtimes.h
/usr/include/./x86_64-linux-gnu/sys/dir.h
/usr/include/./x86_64-linux-gnu/sys/fsuid.h
/usr/include/./x86_64-linux-gnu/jconfig.h
/usr/include/./x86_64-linux-gnu/c++
/usr/include/./x86_64-linux-gnu/c++/5.2.1
/usr/include/./x86_64-linux-gnu/c++/5
/usr/include/./x86_64-linux-gnu/c++/5/bits
/usr/include/./x86_64-linux-gnu/c++/5/bits/stdtr1c++.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/cxxabi_tweaks.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/c++locale.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/gthr.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/c++config.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/ctype_inline.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/messages_members.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/gthr-default.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/time_members.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/gthr-single.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/stdc++.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/ctype_base.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/basic_file.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/gthr-posix.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/c++io.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/atomic_word.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/c++allocator.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/opt_random.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/os_defines.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/error_constants.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/extc++.h
/usr/include/./x86_64-linux-gnu/c++/5/bits/cpu_defines.h
/usr/include/./x86_64-linux-gnu/c++/5/ext
/usr/include/./x86_64-linux-gnu/c++/5/ext/opt_random.h
/usr/include/./x86_64-linux-gnu/fpu_control.h
/usr/include/./x86_64-linux-gnu/asm
/usr/include/./x86_64-linux-gnu/asm/kvm_para.h
/usr/include/./x86_64-linux-gnu/asm/hyperv.h
/usr/include/./x86_64-linux-gnu/asm/bitsperlong.h
/usr/include/./x86_64-linux-gnu/asm/statfs.h
/usr/include/./x86_64-linux-gnu/asm/hw_breakpoint.h
/usr/include/./x86_64-linux-gnu/asm/kvm_perf.h
/usr/include/./x86_64-linux-gnu/asm/ucontext.h
/usr/include/./x86_64-linux-gnu/asm/ioctls.h
/usr/include/./x86_64-linux-gnu/asm/poll.h
/usr/include/./x86_64-linux-gnu/asm/processor-flags.h
/usr/include/./x86_64-linux-gnu/asm/byteorder.h
/usr/include/./x86_64-linux-gnu/asm/sockios.h
/usr/include/./x86_64-linux-gnu/asm/kvm.h
/usr/include/./x86_64-linux-gnu/asm/ioctl.h
/usr/include/./x86_64-linux-gnu/asm/sembuf.h
/usr/include/./x86_64-linux-gnu/asm/posix_types_x32.h
/usr/include/./x86_64-linux-gnu/asm/e820.h
/usr/include/./x86_64-linux-gnu/asm/mman.h
/usr/include/./x86_64-linux-gnu/asm/msr.h
/usr/include/./x86_64-linux-gnu/asm/termbits.h
/usr/include/./x86_64-linux-gnu/asm/param.h
/usr/include/./x86_64-linux-gnu/asm/resource.h
/usr/include/./x86_64-linux-gnu/asm/ipcbuf.h
/usr/include/./x86_64-linux-gnu/asm/ist.h
/usr/include/./x86_64-linux-gnu/asm/boot.h
/usr/include/./x86_64-linux-gnu/asm/ptrace.h
/usr/include/./x86_64-linux-gnu/asm/siginfo.h
/usr/include/./x86_64-linux-gnu/asm/mce.h
/usr/include/./x86_64-linux-gnu/asm/a.out.h
/usr/include/./x86_64-linux-gnu/asm/prctl.h
/usr/include/./x86_64-linux-gnu/asm/svm.h
/usr/include/./x86_64-linux-gnu/asm/fcntl.h
/usr/include/./x86_64-linux-gnu/asm/posix_types.h
/usr/include/./x86_64-linux-gnu/asm/ptrace-abi.h
/usr/include/./x86_64-linux-gnu/asm/vmx.h
/usr/include/./x86_64-linux-gnu/asm/posix_types_32.h
/usr/include/./x86_64-linux-gnu/asm/errno.h
/usr/include/./x86_64-linux-gnu/asm/sigcontext.h
/usr/include/./x86_64-linux-gnu/asm/msr-index.h
/usr/include/./x86_64-linux-gnu/asm/swab.h
/usr/include/./x86_64-linux-gnu/asm/unistd_64.h
/usr/include/./x86_64-linux-gnu/asm/unistd.h
/usr/include/./x86_64-linux-gnu/asm/mtrr.h
/usr/include/./x86_64-linux-gnu/asm/posix_types_64.h
/usr/include/./x86_64-linux-gnu/asm/setup.h
/usr/include/./x86_64-linux-gnu/asm/msgbuf.h
/usr/include/./x86_64-linux-gnu/asm/unistd_32.h
/usr/include/./x86_64-linux-gnu/asm/auxvec.h
/usr/include/./x86_64-linux-gnu/asm/bootparam.h
/usr/include/./x86_64-linux-gnu/asm/debugreg.h
/usr/include/./x86_64-linux-gnu/asm/shmbuf.h
/usr/include/./x86_64-linux-gnu/asm/termios.h
/usr/include/./x86_64-linux-gnu/asm/vm86.h
/usr/include/./x86_64-linux-gnu/asm/signal.h
/usr/include/./x86_64-linux-gnu/asm/perf_regs.h
/usr/include/./x86_64-linux-gnu/asm/vsyscall.h
/usr/include/./x86_64-linux-gnu/asm/types.h
/usr/include/./x86_64-linux-gnu/asm/socket.h
/usr/include/./x86_64-linux-gnu/asm/stat.h
/usr/include/./x86_64-linux-gnu/asm/unistd_x32.h
/usr/include/./x86_64-linux-gnu/asm/ldt.h
/usr/include/./x86_64-linux-gnu/asm/sigcontext32.h
/usr/include/./x86_64-linux-gnu/ieee754.h
/usr/include/./tld.h
/usr/include/./netipx
/usr/include/./netipx/ipx.h
/usr/include/./_G_config.h
/usr/include/./bzlib.h
/usr/include/./prelude-lml
/usr/include/./prelude-lml/prelude-lml.h
/usr/include/./dlg_keys.h
/usr/include/./jmorecfg.h
/usr/include/./utmpx.h
.
./check_wtmpx
./chkproc
./chklastlog
./chkwtmp
./chkdirs
./chkutmp
./ifpromisc
./strings-static
###
### Output of: /bin/ls -l /usr/lib/tcl5.3
###
/bin/ls: cannot access /usr/lib/tcl5.3: No such file or directory
###
### Output of: /bin/ls -l //usr/local/sbin/rootedoor
###
/bin/ls: cannot access //usr/local/sbin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l //usr/local/bin/rootedoor
###
/bin/ls: cannot access //usr/local/bin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l //usr/sbin/rootedoor
###
/bin/ls: cannot access //usr/sbin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l //usr/bin/rootedoor
###
/bin/ls: cannot access //usr/bin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l //sbin/rootedoor
###
/bin/ls: cannot access //sbin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l //bin/rootedoor
###
/bin/ls: cannot access //bin/rootedoor: No such file or directory
###
### Output of: /bin/ls -l /etc/.enyeOCULTAR.ko
###
/bin/ls: cannot access /etc/.enyeOCULTAR.ko: No such file or directory
###
### Output of: /usr/bin/ssh -G 2>&1  | grep -e illegal -e unknow
###
###
### Output of: /usr/bin/find //tmp //var/tmp  -name vuln.txt -o -name ssh-scan -o -name pscan2
###
###
### Output of: /usr/bin/find //home/ruut -maxdepth 1 -name .*history  -size 0
###
###
### Output of: /usr/bin/find //home/ruut -maxdepth 1 -name .*history  \( -links 2 -o -type l \)
###
###
### Output of: /bin/egrep ^asp /etc/inetd.conf
###
###
### Output of: /usr/bin/strings -a asp
###
/usr/bin/strings: 'asp': No such file
###
### Output of: /bin/netstat -an
###
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address          Foreign Address        State     
tcp        0      0 127.0.0.1:587          0.0.0.0:*              LISTEN   
tcp        0      0 127.0.1.1:53            0.0.0.0:*              LISTEN   
tcp        0      0 127.0.0.1:631          0.0.0.0:*              LISTEN   
tcp        0      0 127.0.0.1:25            0.0.0.0:*              LISTEN   
tcp        1      0 192.168.178.20:57132    91.189.94.25:80        CLOSE_WAIT
tcp6      0      0 :::3142                :::*                    LISTEN   
tcp6      0      0 ::1:631                :::*                    LISTEN   
udp        0      0 0.0.0.0:36708          0.0.0.0:*                         
udp        0      0 127.0.1.1:53            0.0.0.0:*                         
udp        0      0 0.0.0.0:68              0.0.0.0:*                         
udp        0      0 0.0.0.0:60434          0.0.0.0:*                         
udp        0      0 0.0.0.0:5353            0.0.0.0:*                         
udp6      0      0 :::44591                :::*                             
udp6      0      0 :::33616                :::*                             
udp6      0      0 :::5353                :::*                             
raw        0      0 0.0.0.0:255            0.0.0.0:*              7         
raw6      0      0 :::58                  :::*                    7         
raw6      0      0 :::255                  :::*                    7         
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags      Type      State        I-Node  Path
unix  2      [ ]        DGRAM                    18995    /run/user/1000/systemd/notify
unix  2      [ ACC ]    STREAM    LISTENING    18996    /run/user/1000/systemd/private
unix  2      [ ACC ]    SEQPACKET  LISTENING    10485    /run/udev/control
unix  2      [ ACC ]    STREAM    LISTENING    19025    /run/user/1000/keyring/control
unix  2      [ ACC ]    STREAM    LISTENING    17184    /tmp/.X11-unix/X0
unix  2      [ ACC ]    STREAM    LISTENING    3178285  /tmp/aptdaemon-hKA7W_/debconf.socket
unix  2      [ ACC ]    STREAM    LISTENING    19264    /run/user/1000/keyring/pkcs11
unix  2      [ ACC ]    STREAM    LISTENING    14057    /sys/fs/cgroup/cgmanager/sock
unix  2      [ ACC ]    STREAM    LISTENING    19266    /run/user/1000/keyring/ssh
unix  2      [ ACC ]    STREAM    LISTENING    20155    /run/user/1000/pulse/native
unix  2      [ ACC ]    STREAM    LISTENING    19183    /tmp/gpg-LYCBI3/S.gpg-agent
unix  2      [ ACC ]    STREAM    LISTENING    155592  /var/run/fail2ban/fail2ban.sock
unix  2      [ ACC ]    STREAM    LISTENING    20058    /tmp/.ICE-unix/1803
unix  2      [ ACC ]    STREAM    LISTENING    20057    @/tmp/.ICE-unix/1803
unix  2      [ ACC ]    STREAM    LISTENING    17183    @/tmp/.X11-unix/X0
unix  2      [ ACC ]    STREAM    LISTENING    1382143  /tmp/.vbox-ruut-ipc/ipcd
unix  2      [ ACC ]    STREAM    LISTENING    263089  /var/run/clamav/clamav-milter.ctl
unix  2      [ ACC ]    STREAM    LISTENING    31302    @/tmp/dbus-spzT7OkGtL
unix  2      [ ACC ]    STREAM    LISTENING    262853  /run/clamav/clamd.ctl
unix  2      [ ACC ]    STREAM    LISTENING    19806    @/tmp/dbus-hdL1ikuldS
unix  2      [ ACC ]    STREAM    LISTENING    563003  @ruut-com.canonical.Unity.Scope.files.T54566403189377
unix  2      [ ACC ]    STREAM    LISTENING    19318    @/tmp/dbus-HWsxYgltc7
unix  2      [ ACC ]    STREAM    LISTENING    13654    /run/acpid.socket
unix  2      [ ]        DGRAM                    10470    /run/systemd/notify
unix  2      [ ACC ]    STREAM    LISTENING    10471    /run/systemd/private
unix  2      [ ACC ]    STREAM    LISTENING    10482    /run/systemd/journal/stdout
unix  7      [ ]        DGRAM                    10483    /run/systemd/journal/socket
unix  2      [ ACC ]    STREAM    LISTENING    13655    /run/uuidd/request
unix  2      [ ACC ]    STREAM    LISTENING    13657    /var/run/avahi-daemon/socket
unix  2      [ ACC ]    STREAM    LISTENING    10484    /run/lvm/lvmpolld.socket
unix  2      [ ACC ]    STREAM    LISTENING    13659    /var/run/dbus/system_bus_socket
unix  22    [ ]        DGRAM                    10486    /run/systemd/journal/dev-log
unix  2      [ ACC ]    STREAM    LISTENING    10490    /run/systemd/fsck.progress
unix  2      [ ACC ]    STREAM    LISTENING    10491    /run/lvm/lvmetad.socket
unix  2      [ ACC ]    STREAM    LISTENING    19769    @/com/ubuntu/upstart-session/1000/1616
unix  2      [ ]        DGRAM                    9891    /run/systemd/journal/syslog
unix  2      [ ACC ]    STREAM    LISTENING    220957  /var/run/cups/cups.sock
unix  2      [ ACC ]    STREAM    LISTENING    599726  @ruut-com.canonical.Unity.Master.Scope.applications.T54564518794383
unix  2      [ ACC ]    STREAM    LISTENING    599767  @ruut-com.canonical.Unity.Scope.scopes.T54564604745408
unix  2      [ ACC ]    STREAM    LISTENING    16510    /var/run/NetworkManager/private
unix  2      [ ACC ]    STREAM    LISTENING    16868    /var/run/NetworkManager/private-dhcp
unix  2      [ ACC ]    STREAM    LISTENING    599733  @ruut-com.canonical.Unity.Master.Scope.files.T54564521425825
unix  2      [ ACC ]    STREAM    LISTENING    19867    @/tmp/dbus-HrCqHDIX
unix  2      [ ACC ]    STREAM    LISTENING    599764  @ruut-com.canonical.Unity.Scope.applications.T54564593521530
unix  2      [ ACC ]    STREAM    LISTENING    469064  @ruut-com.canonical.Unity.Scope.applications.T54240662904203
unix  2      [ ACC ]    STREAM    LISTENING    4030452  @ruut-com.canonical.Unity.Master.Scope.music.T62797063523039
unix  2      [ ACC ]    STREAM    LISTENING    469065  @ruut-com.canonical.Unity.Scope.scopes.T54240773952
unix  2      [ ACC ]    STREAM    LISTENING    20437    /var/run/sendmail/mta/smcontrol
unix  3      [ ]        DGRAM                    1370266 
unix  3      [ ]        STREAM    CONNECTED    221419 
unix  3      [ ]        STREAM    CONNECTED    220953  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    146313  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    119855 
unix  3      [ ]        STREAM    CONNECTED    21518    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20458   
unix  3      [ ]        STREAM    CONNECTED    19943   
unix  3      [ ]        STREAM    CONNECTED    21356   
unix  3      [ ]        STREAM    CONNECTED    20934    @/tmp/.X11-unix/X0
unix  2      [ ]        DGRAM                    10936   
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    22915   
unix  3      [ ]        STREAM    CONNECTED    16449   
unix  3      [ ]        STREAM    CONNECTED    21938   
unix  3      [ ]        STREAM    CONNECTED    20290    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20563    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21085    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20860   
unix  3      [ ]        STREAM    CONNECTED    18424   
unix  3      [ ]        STREAM    CONNECTED    15328   
unix  3      [ ]        STREAM    CONNECTED    20152    @/tmp/.X11-unix/X0
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        DGRAM                    340522 
unix  3      [ ]        STREAM    CONNECTED    22682   
unix  3      [ ]        STREAM    CONNECTED    18421    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20352    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    14006    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    108703  @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    22876   
unix  3      [ ]        STREAM    CONNECTED    20283   
unix  3      [ ]        STREAM    CONNECTED    20258   
unix  3      [ ]        STREAM    CONNECTED    20252    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    19847    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    155044 
unix  3      [ ]        STREAM    CONNECTED    119848  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    22997    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21530   
unix  3      [ ]        STREAM    CONNECTED    20276   
unix  3      [ ]        STREAM    CONNECTED    19293    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    15061   
unix  3      [ ]        STREAM    CONNECTED    599742  @ruut-com.canonical.Unity.Master.Scope.applications.T54564518794383
unix  3      [ ]        STREAM    CONNECTED    108487  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1772183  @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    19336   
unix  3      [ ]        STREAM    CONNECTED    19160   
unix  3      [ ]        STREAM    CONNECTED    2410483  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    164059 
unix  3      [ ]        STREAM    CONNECTED    22787    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    21625    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21506    /run/systemd/journal/stdout
unix  2      [ ]        DGRAM                    1787512 
unix  3      [ ]        STREAM    CONNECTED    23005    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21342   
unix  3      [ ]        STREAM    CONNECTED    20686   
unix  3      [ ]        STREAM    CONNECTED    19871    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21413   
unix  3      [ ]        STREAM    CONNECTED    17597    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    108701  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20643    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19973   
unix  3      [ ]        STREAM    CONNECTED    15329    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    5243642 
unix  3      [ ]        STREAM    CONNECTED    18425    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21152   
unix  3      [ ]        STREAM    CONNECTED    600429  @ruut-com.canonical.Unity.Scope.files.T54566403189377
unix  3      [ ]        STREAM    CONNECTED    119861  /run/systemd/journal/stdout
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    1382144 
unix  3      [ ]        STREAM    CONNECTED    232063  @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    19434   
unix  3      [ ]        STREAM    CONNECTED    2699145 
unix  3      [ ]        STREAM    CONNECTED    22879   
unix  3      [ ]        STREAM    CONNECTED    20249    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19451    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    19849   
unix  3      [ ]        STREAM    CONNECTED    4030453 
unix  3      [ ]        STREAM    CONNECTED    145157 
unix  3      [ ]        STREAM    CONNECTED    108696 
unix  3      [ ]        STREAM    CONNECTED    21812   
unix  3      [ ]        STREAM    CONNECTED    20466   
unix  3      [ ]        STREAM    CONNECTED    19454    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19288    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        DGRAM                    13509   
unix  3      [ ]        STREAM    CONNECTED    2719462 
unix  3      [ ]        STREAM    CONNECTED    308681  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20672    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    17496    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21922    @/dbus-vfs-daemon/socket-cjFpCW8G
unix  3      [ ]        STREAM    CONNECTED    2719463  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    1786729  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1370184 
unix  3      [ ]        STREAM    CONNECTED    464362 
unix  3      [ ]        STREAM    CONNECTED    119864  @/tmp/dbus-hdL1ikuldS
unix  2      [ ]        DGRAM                    20327   
unix  3      [ ]        STREAM    CONNECTED    20022   
unix  3      [ ]        STREAM    CONNECTED    15463    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20825    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    32380   
unix  3      [ ]        STREAM    CONNECTED    16511   
unix  3      [ ]        STREAM    CONNECTED    19374   
unix  3      [ ]        STREAM    CONNECTED    21075   
unix  3      [ ]        STREAM    CONNECTED    220946  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20629   
unix  2      [ ]        DGRAM                    16185   
unix  3      [ ]        STREAM    CONNECTED    21932    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21664    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    32392   
unix  3      [ ]        STREAM    CONNECTED    119042 
unix  3      [ ]        STREAM    CONNECTED    19980   
unix  3      [ ]        STREAM    CONNECTED    19976   
unix  3      [ ]        STREAM    CONNECTED    220968 
unix  3      [ ]        STREAM    CONNECTED    20330    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    119046 
unix  3      [ ]        STREAM    CONNECTED    19634    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    14748    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1383759  /tmp/.vbox-ruut-ipc/ipcd
unix  3      [ ]        STREAM    CONNECTED    17561   
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    232684 
unix  3      [ ]        STREAM    CONNECTED    108485  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21362    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20669    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    1782160 
unix  3      [ ]        STREAM    CONNECTED    2410482 
unix  3      [ ]        STREAM    CONNECTED    1370204  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    221414 
unix  3      [ ]        STREAM    CONNECTED    21789    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    21637    @/tmp/dbus-hdL1ikuldS
unix  2      [ ]        DGRAM                    14028   
unix  3      [ ]        STREAM    CONNECTED    31118    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    20930   
unix  3      [ ]        STREAM    CONNECTED    22031   
unix  3      [ ]        STREAM    CONNECTED    16850   
unix  3      [ ]        STREAM    CONNECTED    411414 
unix  3      [ ]        STREAM    CONNECTED    21461   
unix  3      [ ]        STREAM    CONNECTED    20443   
unix  3      [ ]        STREAM    CONNECTED    21931   
unix  3      [ ]        STREAM    CONNECTED    21148    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    15327   
unix  3      [ ]        STREAM    CONNECTED    22874    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19368    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    146277  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    31303   
unix  3      [ ]        STREAM    CONNECTED    20987    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    21473    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20271   
unix  3      [ ]        STREAM    CONNECTED    19325   
unix  3      [ ]        STREAM    CONNECTED    232683  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    22857   
unix  3      [ ]        STREAM    CONNECTED    20264    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20145    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    19969   
unix  3      [ ]        STREAM    CONNECTED    19161    /var/run/dbus/system_bus_socket
unix  2      [ ]        DGRAM                    19627   
unix  3      [ ]        STREAM    CONNECTED    23056    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20640   
unix  3      [ ]        STREAM    CONNECTED    19165   
unix  3      [ ]        STREAM    CONNECTED    21183    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    20611    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    13151   
unix  3      [ ]        STREAM    CONNECTED    232673 
unix  3      [ ]        STREAM    CONNECTED    20861    @/tmp/.ICE-unix/1803
unix  3      [ ]        DGRAM                    340521 
unix  3      [ ]        STREAM    CONNECTED    19547    /var/run/dbus/system_bus_socket
unix  3      [ ]        DGRAM                    1370265 
unix  3      [ ]        STREAM    CONNECTED    221409  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    146279 
unix  3      [ ]        STREAM    CONNECTED    21442   
unix  3      [ ]        STREAM    CONNECTED    19331    @/tmp/.X11-unix/X0
unix  3      [ ]        DGRAM                    11317   
unix  3      [ ]        STREAM    CONNECTED    464361 
unix  3      [ ]        STREAM    CONNECTED    21357   
unix  3      [ ]        STREAM    CONNECTED    20792    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    1795239 
unix  3      [ ]        STREAM    CONNECTED    308700 
unix  3      [ ]        STREAM    CONNECTED    232681 
unix  3      [ ]        STREAM    CONNECTED    119037 
unix  3      [ ]        STREAM    CONNECTED    21806    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20160    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19846   
unix  3      [ ]        STREAM    CONNECTED    599817 
unix  3      [ ]        STREAM    CONNECTED    19350    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19195    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21522   
unix  3      [ ]        STREAM    CONNECTED    20534    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    19292   
unix  3      [ ]        STREAM    CONNECTED    10064    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20990    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    23034   
unix  3      [ ]        STREAM    CONNECTED    22654   
unix  3      [ ]        STREAM    CONNECTED    20342    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21082   
unix  3      [ ]        STREAM    CONNECTED    16155    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20642   
unix  3      [ ]        STREAM    CONNECTED    19125   
unix  3      [ ]        STREAM    CONNECTED    14012   
unix  3      [ ]        STREAM    CONNECTED    20931    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    1779708 
unix  3      [ ]        STREAM    CONNECTED    108499 
unix  3      [ ]        STREAM    CONNECTED    21482    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20133   
unix  3      [ ]        STREAM    CONNECTED    1390216  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    220983 
unix  3      [ ]        STREAM    CONNECTED    146311  @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    21760   
unix  3      [ ]        STREAM    CONNECTED    21468   
unix  3      [ ]        STREAM    CONNECTED    1787520 
unix  3      [ ]        STREAM    CONNECTED    119049 
unix  3      [ ]        STREAM    CONNECTED    15314   
unix  3      [ ]        STREAM    CONNECTED    21354   
unix  3      [ ]        STREAM    CONNECTED    20310    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    10929   
unix  3      [ ]        STREAM    CONNECTED    562986  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20454    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    17495   
unix  3      [ ]        STREAM    CONNECTED    21810    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21248    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20581    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    20156   
unix  3      [ ]        STREAM    CONNECTED    562996 
unix  3      [ ]        STREAM    CONNECTED    599741 
unix  3      [ ]        STREAM    CONNECTED    21467   
unix  3      [ ]        STREAM    CONNECTED    119856  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21459    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19435    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    19287   
unix  3      [ ]        STREAM    CONNECTED    108493 
unix  3      [ ]        STREAM    CONNECTED    599852  @ruut-com.canonical.Unity.Scope.scopes.T54564604745408
unix  3      [ ]        STREAM    CONNECTED    19987   
unix  3      [ ]        STREAM    CONNECTED    16210   
unix  3      [ ]        STREAM    CONNECTED    18426   
unix  3      [ ]        STREAM    CONNECTED    232058  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20826   
unix  2      [ ]        DGRAM                    18989   
unix  3      [ ]        STREAM    CONNECTED    15591    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20646   
unix  3      [ ]        STREAM    CONNECTED    20005    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21076    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    20610   
unix  2      [ ]        DGRAM                    16830   
unix  3      [ ]        STREAM    CONNECTED    463482  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    119052  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20673   
unix  2      [ ]        STREAM    CONNECTED    4921556 
unix  3      [ ]        STREAM    CONNECTED    23019   
unix  3      [ ]        STREAM    CONNECTED    1370180  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    221422  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    119050 
unix  3      [ ]        STREAM    CONNECTED    21534    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21395   
unix  2      [ ]        DGRAM                    16448   
unix  3      [ ]        STREAM    CONNECTED    119851  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20272    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19977    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    148344  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20957   
unix  3      [ ]        STREAM    CONNECTED    22861   
unix  3      [ ]        STREAM    CONNECTED    20261   
unix  3      [ ]        STREAM    CONNECTED    20518   
unix  3      [ ]        STREAM    CONNECTED    19240    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19622   
unix  3      [ ]        STREAM    CONNECTED    1382146  /tmp/.vbox-ruut-ipc/ipcd
unix  3      [ ]        STREAM    CONNECTED    562988  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19168    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    108699 
unix  2      [ ]        DGRAM                    5001493 
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    22713   
unix  3      [ ]        STREAM    CONNECTED    19990    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    108495 
unix  3      [ ]        STREAM    CONNECTED    20885   
unix  3      [ ]        STREAM    CONNECTED    19948    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20447   
unix  3      [ ]        STREAM    CONNECTED    463555 
unix  3      [ ]        STREAM    CONNECTED    20831   
unix  3      [ ]        STREAM    CONNECTED    20153   
unix  2      [ ]        DGRAM                    308694 
unix  3      [ ]        STREAM    CONNECTED    21434    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20618    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    411444  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19369   
unix  3      [ ]        STREAM    CONNECTED    469134  @ruut-com.canonical.Unity.Scope.scopes.T54240773952
unix  3      [ ]        STREAM    CONNECTED    308701  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20460    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    19263   
unix  3      [ ]        STREAM    CONNECTED    14300    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    32394    @/tmp/.X11-unix/X0
unix  2      [ ]        DGRAM                    17907   
unix  3      [ ]        STREAM    CONNECTED    1772386 
unix  3      [ ]        STREAM    CONNECTED    1772186  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    146312 
unix  3      [ ]        STREAM    CONNECTED    21788   
unix  3      [ ]        STREAM    CONNECTED    21503    @/tmp/dbus-hdL1ikuldS
unix  2      [ ]        DGRAM                    20311   
unix  3      [ ]        STREAM    CONNECTED    599738 
unix  3      [ ]        STREAM    CONNECTED    145151 
unix  3      [ ]        STREAM    CONNECTED    20986   
unix  3      [ ]        STREAM    CONNECTED    20306   
unix  3      [ ]        STREAM    CONNECTED    21910   
unix  3      [ ]        STREAM    CONNECTED    21630    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    20269    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19324   
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    1379806  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    599818 
unix  3      [ ]        STREAM    CONNECTED    21177    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    15333    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    119040 
unix  3      [ ]        STREAM    CONNECTED    22858    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    20265   
unix  3      [ ]        STREAM    CONNECTED    20561   
unix  3      [ ]        STREAM    CONNECTED    19842    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    221407 
unix  3      [ ]        STREAM    CONNECTED    21147   
unix  3      [ ]        STREAM    CONNECTED    1199814 
unix  3      [ ]        STREAM    CONNECTED    21667    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    20004   
unix  3      [ ]        STREAM    CONNECTED    22655    @/dbus-vfs-daemon/socket-ZpqNbMpe
unix  3      [ ]        STREAM    CONNECTED    20577   
unix  3      [ ]        STREAM    CONNECTED    102124 
unix  3      [ ]        STREAM    CONNECTED    13994    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    108702 
unix  3      [ ]        STREAM    CONNECTED    19237   
unix  3      [ ]        STREAM    CONNECTED    469133 
unix  3      [ ]        STREAM    CONNECTED    22810   
unix  3      [ ]        STREAM    CONNECTED    20571    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1379805 
unix  3      [ ]        STREAM    CONNECTED    599841 
unix  3      [ ]        STREAM    CONNECTED    20074    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    17488    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    119041 
unix  3      [ ]        STREAM    CONNECTED    20469   
unix  3      [ ]        STREAM    CONNECTED    20149   
unix  3      [ ]        STREAM    CONNECTED    19347    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    19220   
unix  3      [ ]        STREAM    CONNECTED    21011    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    1370305 
unix  3      [ ]        STREAM    CONNECTED    22788    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    21476   
unix  3      [ ]        STREAM    CONNECTED    19385    @/tmp/dbus-hdL1ikuldS
unix  2      [ ]        DGRAM                    16441   
unix  3      [ ]        STREAM    CONNECTED    1786731  /run/systemd/journal/stdout
unix  2      [ ]        DGRAM                    21360   
unix  3      [ ]        STREAM    CONNECTED    20935   
unix  3      [ ]        STREAM    CONNECTED    23004   
unix  3      [ ]        STREAM    CONNECTED    15330    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21505    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20288    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    18846   
unix  3      [ ]        STREAM    CONNECTED    21247   
unix  3      [ ]        STREAM    CONNECTED    20614    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    32393   
unix  3      [ ]        STREAM    CONNECTED    20832    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    21111   
unix  3      [ ]        STREAM    CONNECTED    14961   
unix  3      [ ]        STREAM    CONNECTED    600428 
unix  3      [ ]        STREAM    CONNECTED    19365    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    16135   
unix  3      [ ]        STREAM    CONNECTED    232062 
unix  3      [ ]        STREAM    CONNECTED    15760   
unix  3      [ ]        STREAM    CONNECTED    2719769  @/dbus-vfs-daemon/socket-QyhR3LsN
unix  3      [ ]        STREAM    CONNECTED    119047  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20791   
unix  3      [ ]        STREAM    CONNECTED    20633    /run/user/1000/pulse/native
unix  3      [ ]        STREAM    CONNECTED    19971   
unix  3      [ ]        STREAM    CONNECTED    19518    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21020   
unix  3      [ ]        STREAM    CONNECTED    20030   
unix  3      [ ]        STREAM    CONNECTED    23206   
unix  3      [ ]        STREAM    CONNECTED    20142   
unix  3      [ ]        STREAM    CONNECTED    19946    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    23207    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    19167   
unix  2      [ ]        STREAM    CONNECTED    5001490 
unix  3      [ ]        STREAM    CONNECTED    1772387 
unix  3      [ ]        STREAM    CONNECTED    1777643  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    22714    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    1787586  @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    232682  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    18778    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    464513 
unix  3      [ ]        STREAM    CONNECTED    308708  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20299    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21083    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    20647    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    17265   
unix  3      [ ]        STREAM    CONNECTED    21804   
unix  3      [ ]        STREAM    CONNECTED    20444    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    19338   
unix  3      [ ]        STREAM    CONNECTED    22081   
unix  3      [ ]        STREAM    CONNECTED    20886    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19394    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    16839    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    21662    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19373    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    21151   
unix  3      [ ]        STREAM    CONNECTED    15012   
unix  3      [ ]        STREAM    CONNECTED    22995    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21529   
unix  3      [ ]        STREAM    CONNECTED    20132   
unix  3      [ ]        STREAM    CONNECTED    19335   
unix  3      [ ]        STREAM    CONNECTED    4030454  @ruut-com.canonical.Unity.Master.Scope.music.T62797063523039
unix  3      [ ]        STREAM    CONNECTED    1370179 
unix  3      [ ]        STREAM    CONNECTED    308696 
unix  3      [ ]        STREAM    CONNECTED    21101    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    22859   
unix  3      [ ]        STREAM    CONNECTED    20262    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20566    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20519    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    1370267  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    599842  @ruut-com.canonical.Unity.Scope.applications.T54564593521530
unix  3      [ ]        STREAM    CONNECTED    462089 
unix  3      [ ]        STREAM    CONNECTED    15754   
unix  3      [ ]        STREAM    CONNECTED    14082   
unix  3      [ ]        STREAM    CONNECTED    1383756 
unix  3      [ ]        STREAM    CONNECTED    21436   
unix  3      [ ]        STREAM    CONNECTED    14299   
unix  3      [ ]        STREAM    CONNECTED    10934    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    108695 
unix  3      [ ]        STREAM    CONNECTED    13833   
unix  3      [ ]        STREAM    CONNECTED    1370203 
unix  3      [ ]        STREAM    CONNECTED    220972 
unix  3      [ ]        STREAM    CONNECTED    119867  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21796    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21627    @/dbus-vfs-daemon/socket-CYxQsFiz
unix  3      [ ]        STREAM    CONNECTED    20391   
unix  3      [ ]        STREAM    CONNECTED    1772215  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    22650   
unix  3      [ ]        STREAM    CONNECTED    463480  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    232065  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20864    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    21396    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19114   
unix  3      [ ]        STREAM    CONNECTED    22872    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19382   
unix  3      [ ]        STREAM    CONNECTED    31116    @/tmp/dbus-HWsxYgltc7
unix  2      [ ]        DGRAM                    21078   
unix  3      [ ]        STREAM    CONNECTED    411413 
unix  3      [ ]        STREAM    CONNECTED    22029   
unix  3      [ ]        STREAM    CONNECTED    232676 
unix  3      [ ]        STREAM    CONNECTED    23035    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    22674   
unix  3      [ ]        STREAM    CONNECTED    147343 
unix  3      [ ]        STREAM    CONNECTED    20989   
unix  3      [ ]        STREAM    CONNECTED    21904    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21523    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20560    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        DGRAM                    13508   
unix  3      [ ]        STREAM    CONNECTED    17588    /run/acpid.socket
unix  3      [ ]        STREAM    CONNECTED    14144    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    22877   
unix  3      [ ]        STREAM    CONNECTED    20612    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20157   
unix  3      [ ]        STREAM    CONNECTED    20562    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19812   
unix  3      [ ]        DGRAM                    13510   
unix  2      [ ]        DGRAM                    3461558 
unix  3      [ ]        STREAM    CONNECTED    108500 
unix  3      [ ]        STREAM    CONNECTED    19970    @/tmp/.X11-unix/X0
unix  2      [ ]        DGRAM                    15324   
unix  3      [ ]        STREAM    CONNECTED    21384    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20392   
unix  3      [ ]        STREAM    CONNECTED    19261   
unix  3      [ ]        STREAM    CONNECTED    15430    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1370227 
unix  3      [ ]        STREAM    CONNECTED    22619   
unix  3      [ ]        STREAM    CONNECTED    20307    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    22652   
unix  3      [ ]        STREAM    CONNECTED    19117    @/com/ubuntu/upstart-session/1000/1616
unix  3      [ ]        STREAM    CONNECTED    20827    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    13479    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    411446  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20446    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19370    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    22811    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    20248   
unix  3      [ ]        STREAM    CONNECTED    19450   
unix  3      [ ]        STREAM    CONNECTED    19770   
unix  3      [ ]        STREAM    CONNECTED    19194   
unix  3      [ ]        STREAM    CONNECTED    17487   
unix  3      [ ]        STREAM    CONNECTED    119854  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21460    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20624    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19291   
unix  3      [ ]        STREAM    CONNECTED    9996   
unix  3      [ ]        STREAM    CONNECTED    562997  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    599743  @ruut-com.canonical.Unity.Master.Scope.files.T54564521425825
unix  3      [ ]        STREAM    CONNECTED    21010   
unix  3      [ ]        STREAM    CONNECTED    19989   
unix  3      [ ]        STREAM    CONNECTED    14901    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    32101   
unix  3      [ ]        STREAM    CONNECTED    19945   
unix  3      [ ]        STREAM    CONNECTED    20462    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20639   
unix  3      [ ]        STREAM    CONNECTED    19515    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21508    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21100   
unix  3      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  3      [ ]        STREAM    CONNECTED    31117   
unix  3      [ ]        STREAM    CONNECTED    20863   
unix  3      [ ]        STREAM    CONNECTED    21638    @/dbus-vfs-daemon/socket-LgBY86qL
unix  3      [ ]        STREAM    CONNECTED    18921   
unix  2      [ ]        DGRAM                    16509   
unix  3      [ ]        STREAM    CONNECTED    1772187 
unix  3      [ ]        STREAM    CONNECTED    220976  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    220969  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    146310 
unix  3      [ ]        STREAM    CONNECTED    21761   
unix  3      [ ]        STREAM    CONNECTED    21527    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20448    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    16442   
unix  3      [ ]        STREAM    CONNECTED    462090  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    21361   
unix  3      [ ]        STREAM    CONNECTED    20933   
unix  3      [ ]        STREAM    CONNECTED    14010    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    119038  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21829    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    20573   
unix  3      [ ]        STREAM    CONNECTED    232064 
unix  3      [ ]        STREAM    CONNECTED    21343    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    15755    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21811    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21443    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20936    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19346    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19517   
unix  3      [ ]        STREAM    CONNECTED    22617   
unix  3      [ ]        STREAM    CONNECTED    21021    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21813    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21629   
unix  3      [ ]        STREAM    CONNECTED    20076   
unix  3      [ ]        STREAM    CONNECTED    15528    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21112    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19974    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    599851 
unix  3      [ ]        STREAM    CONNECTED    18420   
unix  3      [ ]        STREAM    CONNECTED    19243   
unix  3      [ ]        STREAM    CONNECTED    108700  @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    21084   
unix  3      [ ]        STREAM    CONNECTED    20617   
unix  2      [ ]        DGRAM                    16964   
unix  3      [ ]        STREAM    CONNECTED    21444   
unix  3      [ ]        STREAM    CONNECTED    19339    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    31294    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    20151   
unix  3      [ ]        STREAM    CONNECTED    232674  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    22082    @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    1782161  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19330    @/tmp/dbus-HWsxYgltc7
unix  3      [ ]        STREAM    CONNECTED    1772185 
unix  3      [ ]        STREAM    CONNECTED    165008  /run/user/1000/pulse/native
unix  3      [ ]        STREAM    CONNECTED    146280  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    32391   
unix  3      [ ]        STREAM    CONNECTED    21668   
unix  3      [ ]        STREAM    CONNECTED    21470   
unix  3      [ ]        STREAM    CONNECTED    119868 
unix  3      [ ]        STREAM    CONNECTED    15072   
unix  3      [ ]        STREAM    CONNECTED    340576 
unix  3      [ ]        STREAM    CONNECTED    21355   
unix  3      [ ]        STREAM    CONNECTED    21179    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    21909   
unix  3      [ ]        STREAM    CONNECTED    21479    @/tmp/.X11-unix/X0
unix  3      [ ]        DGRAM                    11316   
unix  2      [ ]        DGRAM                    20961   
unix  3      [ ]        STREAM    CONNECTED    21797    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20263   
unix  3      [ ]        STREAM    CONNECTED    20551   
unix  3      [ ]        STREAM    CONNECTED    19128    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    14743   
unix  2      [ ]        STREAM    CONNECTING    0        /run/clamav/clamd.ctl
unix  2      [ ]        DGRAM                    17580   
unix  3      [ ]        STREAM    CONNECTED    23030    /var/run/dbus/system_bus_socket
unix  2      [ ]        DGRAM                    16154   
unix  3      [ ]        STREAM    CONNECTED    23037   
unix  3      [ ]        STREAM    CONNECTED    22675   
unix  3      [ ]        STREAM    CONNECTED    102125  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    14900   
unix  3      [ ]        STREAM    CONNECTED    469078  @ruut-com.canonical.Unity.Scope.applications.T54240662904203
unix  3      [ ]        STREAM    CONNECTED    220980  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    20824   
unix  3      [ ]        STREAM    CONNECTED    32397    @/tmp/dbus-spzT7OkGtL
unix  3      [ ]        STREAM    CONNECTED    16474   
unix  3      [ ]        STREAM    CONNECTED    20279    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    19383    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    19166    @/com/ubuntu/upstart-session/1000/1616
unix  3      [ ]        STREAM    CONNECTED    21182   
unix  3      [ ]        STREAM    CONNECTED    20613   
unix  3      [ ]        STREAM    CONNECTED    340513 
unix  3      [ ]        STREAM    CONNECTED    21392   
unix  3      [ ]        STREAM    CONNECTED    20671   
unix  3      [ ]        STREAM    CONNECTED    1787521  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    14904    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    1378151  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    220952 
unix  3      [ ]        STREAM    CONNECTED    119051 
unix  3      [ ]        STREAM    CONNECTED    21795   
unix  3      [ ]        STREAM    CONNECTED    21502   
unix  3      [ ]        STREAM    CONNECTED    21393    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    20159    /run/user/1000/pulse/native
unix  3      [ ]        STREAM    CONNECTED    1777508 
unix  3      [ ]        STREAM    CONNECTED    19222    @/com/ubuntu/upstart-session/1000/1616
unix  3      [ ]        STREAM    CONNECTED    21023   
unix  3      [ ]        STREAM    CONNECTED    21903   
unix  3      [ ]        STREAM    CONNECTED    21525   
unix  3      [ ]        STREAM    CONNECTED    19452    /run/systemd/journal/stdout
unix  2      [ ]        DGRAM                    13504   
unix  3      [ ]        STREAM    CONNECTED    1384586 
unix  3      [ ]        STREAM    CONNECTED    154108  /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    15761    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    14143   
unix  3      [ ]        STREAM    CONNECTED    21798    @/dbus-vfs-daemon/socket-qd3Q6D8q
unix  3      [ ]        STREAM    CONNECTED    20268   
unix  3      [ ]        STREAM    CONNECTED    20570   
unix  3      [ ]        STREAM    CONNECTED    19082    /var/run/dbus/system_bus_socket
unix  3      [ ]        DGRAM                    13511   
unix  3      [ ]        STREAM    CONNECTED    16957    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    308695 
unix  3      [ ]        STREAM    CONNECTED    221420 
unix  3      [ ]        STREAM    CONNECTED    108494  @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    21660    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19988   
unix  3      [ ]        STREAM    CONNECTED    19124   
unix  3      [ ]        STREAM    CONNECTED    16512    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21024    /run/systemd/journal/stdout
unix  3      [ ]        STREAM    CONNECTED    19172   
unix  3      [ ]        STREAM    CONNECTED    22030    @/tmp/.X11-unix/X0
unix  3      [ ]        STREAM    CONNECTED    22032    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    20445   
unix  2      [ ]        DGRAM                    4921560 
unix  3      [ ]        STREAM    CONNECTED    15332    /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    21383   
unix  3      [ ]        STREAM    CONNECTED    20668   
unix  3      [ ]        STREAM    CONNECTED    19872    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    15409   
unix  3      [ ]        STREAM    CONNECTED    19850    @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    19813    @/com/ubuntu/upstart-session/1000/1616
unix  3      [ ]        STREAM    CONNECTED    1370228  @/tmp/dbus-HrCqHDIX
unix  3      [ ]        STREAM    CONNECTED    464514  @/tmp/dbus-hdL1ikuldS
unix  3      [ ]        STREAM    CONNECTED    220973  /var/run/dbus/system_bus_socket
unix  3      [ ]        STREAM    CONNECTED    145156 
unix  3      [ ]        STREAM    CONNECTED    21803   
unix  3      [ ]        STREAM    CONNECTED    21501   
unix  2      [ ]        STREAM    CONNECTED    20308   
###
### Output of: ./chkproc -v -v -p 3
###
CWD  703: /
EXE  703: /lib/systemd/systemd-timesyncd
CWD  859: /
EXE  859: /usr/sbin/rsyslogd
CWD  860: /
EXE  860: /usr/sbin/rsyslogd
CWD  861: /
EXE  861: /usr/sbin/rsyslogd
CWD  862: /
EXE  862: /usr/lib/accountsservice/accounts-daemon
CWD  870: /
EXE  870: /usr/lib/accountsservice/accounts-daemon
CWD  892: /
EXE  892: /usr/sbin/ModemManager
CWD  894: /
EXE  894: /usr/sbin/ModemManager
CWD  900: /
EXE  900: /usr/lib/policykit-1/polkitd
CWD  902: /
EXE  902: /usr/lib/policykit-1/polkitd
CWD  903: /
EXE  903: /usr/sbin/thermald
CWD  908: /
EXE  908: /usr/sbin/NetworkManager
CWD  936: /
EXE  936: /usr/sbin/NetworkManager
CWD  1284: /
EXE  1284: /usr/sbin/lightdm
CWD  1286: /
EXE  1286: /usr/sbin/lightdm
CWD  1299: /
EXE  1299: /usr/bin/Xorg
CWD  1477: /
EXE  1477: /usr/lib/upower/upowerd
CWD  1478: /
EXE  1478: /usr/lib/upower/upowerd
CWD  1498: /
EXE  1498: /usr/lib/colord/colord
CWD  1500: /
EXE  1500: /usr/lib/colord/colord
CWD  1508: /
EXE  1508: /usr/sbin/lightdm
CWD  1509: /
EXE  1509: /usr/sbin/lightdm
CWD  1610: /
EXE  1610: /usr/bin/gnome-keyring-daemon
CWD  1742: /
EXE  1742: /usr/bin/gnome-keyring-daemon
CWD  1743: /
EXE  1743: /usr/bin/gnome-keyring-daemon
CWD  1744: /
EXE  1744: /usr/bin/gnome-keyring-daemon
CWD  1766: /home/ruut
EXE  1766: /usr/bin/ibus-daemon
CWD  1767: /home/ruut
EXE  1767: /usr/bin/ibus-daemon
CWD  1770: /
EXE  1770: /usr/lib/gvfs/gvfsd
CWD  1771: /
EXE  1771: /usr/lib/gvfs/gvfsd
CWD  1777: /
EXE  1777: /usr/lib/gvfs/gvfsd-fuse
CWD  1778: /
EXE  1778: /usr/lib/gvfs/gvfsd-fuse
CWD  1779: /
EXE  1779: /usr/lib/gvfs/gvfsd-fuse
CWD  1780: /
EXE  1780: /usr/lib/gvfs/gvfsd-fuse
CWD  1781: /
EXE  1781: /usr/lib/gvfs/gvfsd-fuse
CWD  1805: /home/ruut
EXE  1805: /usr/lib/ibus/ibus-dconf
CWD  1806: /home/ruut
EXE  1806: /usr/lib/ibus/ibus-dconf
CWD  1807: /home/ruut
EXE  1807: /usr/lib/at-spi2-core/at-spi-bus-launcher
CWD  1808: /home/ruut
EXE  1808: /usr/lib/at-spi2-core/at-spi-bus-launcher
CWD  1810: /home/ruut
EXE  1810: /usr/lib/at-spi2-core/at-spi-bus-launcher
CWD  1820: /home/ruut
EXE  1820: /usr/lib/at-spi2-core/at-spi2-registryd
CWD  1821: /home/ruut
EXE  1821: /usr/lib/at-spi2-core/at-spi2-registryd
CWD  1827: /home/ruut
EXE  1827: /usr/lib/unity/unity-panel-service
CWD  1828: /home/ruut
EXE  1828: /usr/lib/unity-settings-daemon/unity-settings-daemon
CWD  1829: /home/ruut
EXE  1829: /usr/lib/unity-settings-daemon/unity-settings-daemon
CWD  1830: /home/ruut
EXE  1830: /usr/lib/ibus/ibus-ui-gtk3
CWD  1831: /home/ruut
EXE  1831: /usr/lib/unity/unity-panel-service
CWD  1832: /home/ruut
EXE  1832: /usr/lib/unity/unity-panel-service
CWD  1835: /home/ruut
EXE  1835: /usr/lib/unity-settings-daemon/unity-settings-daemon
CWD  1836: /home/ruut
EXE  1836: /usr/lib/ibus/ibus-ui-gtk3
CWD  1837: /home/ruut
EXE  1837: /usr/lib/ibus/ibus-ui-gtk3
CWD  1842: /home/ruut
EXE  1842: /usr/bin/gnome-session
CWD  1843: /home/ruut
EXE  1843: /usr/bin/gnome-session
CWD  1845: /home/ruut
EXE  1845: /usr/bin/gnome-session
CWD  1848: /home/ruut
EXE  1848: /usr/lib/ibus/ibus-dconf
CWD  1858: /home/ruut
EXE  1858: /usr/lib/ibus/ibus-engine-simple
CWD  1859: /home/ruut
EXE  1859: /usr/lib/ibus/ibus-engine-simple
CWD  1874: /
EXE  1874: /usr/lib/x86_64-linux-gnu/bamf/bamfdaemon
CWD  1875: /
EXE  1875: /usr/lib/x86_64-linux-gnu/bamf/bamfdaemon
CWD  1876: /
EXE  1876: /usr/lib/x86_64-linux-gnu/bamf/bamfdaemon
CWD  1878: /
EXE  1878: /usr/bin/pulseaudio
CWD  1885: /
EXE  1885: /usr/lib/dconf/dconf-service
CWD  1886: /
EXE  1886: /usr/lib/dconf/dconf-service
CWD  1887: /home/ruut
EXE  1887: /usr/bin/compiz
CWD  1896: /home/ruut
EXE  1896: /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
CWD  1898: /home/ruut
EXE  1898: /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
CWD  1899: /home/ruut
EXE  1899: /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
CWD  1903: /home/ruut
EXE  1903: /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
CWD  1904: /home/ruut
EXE  1904: /usr/lib/x86_64-linux-gnu/indicator-session/indicator-session-service
CWD  1905: /home/ruut
EXE  1905: /usr/lib/x86_64-linux-gnu/indicator-session/indicator-session-service
CWD  1916: /home/ruut
EXE  1916: /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
CWD  1917: /home/ruut
EXE  1917: /usr/lib/x86_64-linux-gnu/indicator-session/indicator-session-service
CWD  1918: /home/ruut
EXE  1918: /usr/lib/x86_64-linux-gnu/indicator-sound/indicator-sound-service
CWD  1920: /home/ruut
EXE  1920: /usr/lib/x86_64-linux-gnu/indicator-sound/indicator-sound-service
CWD  1921: /home/ruut
EXE  1921: /usr/lib/x86_64-linux-gnu/indicator-datetime/indicator-datetime-service
CWD  1922: /home/ruut
EXE  1922: /usr/lib/x86_64-linux-gnu/indicator-datetime/indicator-datetime-service
CWD  1924: /home/ruut
EXE  1924: /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
CWD  1925: /home/ruut
EXE  1925: /usr/lib/x86_64-linux-gnu/indicator-datetime/indicator-datetime-service
CWD  1926: /home/ruut
EXE  1926: /usr/lib/x86_64-linux-gnu/indicator-datetime/indicator-datetime-service
CWD  1927: /home/ruut
EXE  1927: /usr/lib/x86_64-linux-gnu/indicator-sound/indicator-sound-service
CWD  1933: /home/ruut
EXE  1933: /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
CWD  1937: /home/ruut
EXE  1937: /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
CWD  1944: /home/ruut
EXE  1944: /usr/lib/x86_64-linux-gnu/indicator-printers/indicator-printers-service
CWD  1945: /home/ruut
EXE  1945: /usr/lib/x86_64-linux-gnu/indicator-printers/indicator-printers-service
CWD  1946: /home/ruut
EXE  1946: /usr/lib/x86_64-linux-gnu/indicator-printers/indicator-printers-service
CWD  1953: /
EXE  1953: /usr/lib/evolution/evolution-source-registry
CWD  1954: /
EXE  1954: /usr/lib/evolution/evolution-source-registry
CWD  1955: /
EXE  1955: /usr/lib/evolution/evolution-source-registry
CWD  1967: /home/ruut
EXE  1967: /usr/lib/ibus/ibus-x11
CWD  1968: /home/ruut
EXE  1968: /usr/lib/ibus/ibus-x11
CWD  1969: /home/ruut
EXE  1969: /usr/lib/ibus/ibus-x11
CWD  1972: /home/ruut
EXE  1972: /usr/lib/x86_64-linux-gnu/hud/hud-service
CWD  1973: /home/ruut
EXE  1973: /usr/lib/x86_64-linux-gnu/hud/hud-service
CWD  1974: /home/ruut
EXE  1974: /usr/lib/x86_64-linux-gnu/hud/hud-service
CWD  1984: /home/ruut
EXE  1984: /usr/bin/compiz
CWD  1985: /home/ruut
EXE  1985: /usr/bin/compiz
CWD  1989: /home/ruut
EXE  1989: /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
CWD  1990: /home/ruut
EXE  1990: /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
CWD  1991: /home/ruut
EXE  1991: /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
CWD  1995: /home/ruut
EXE  1995: /usr/lib/unity-settings-daemon/unity-fallback-mount-helper
CWD  1996: /home/ruut
EXE  1996: /usr/lib/unity-settings-daemon/unity-fallback-mount-helper
CWD  1997: /home/ruut
EXE  1997: /usr/lib/unity-settings-daemon/unity-fallback-mount-helper
CWD  2002: /home/ruut
EXE  2002: /usr/lib/x86_64-linux-gnu/indicator-datetime/indicator-datetime-service
CWD  2011: /home/ruut
EXE  2011: /usr/bin/nm-applet
CWD  2012: /home/ruut
EXE  2012: /usr/bin/nm-applet
CWD  2013: /home/ruut
EXE  2013: /usr/bin/nm-applet
CWD  2037: /
EXE  2037: /usr/lib/evolution/evolution-calendar-factory
CWD  2059: /
EXE  2059: /usr/lib/gvfs/gvfs-udisks2-volume-monitor
CWD  2060: /
EXE  2060: /usr/lib/gvfs/gvfs-udisks2-volume-monitor
CWD  2068: /
EXE  2068: /usr/lib/udisks2/udisksd
CWD  2070: /
EXE  2070: /usr/lib/udisks2/udisksd
CWD  2071: /
EXE  2071: /usr/lib/udisks2/udisksd
CWD  2079: /
EXE  2079: /usr/lib/udisks2/udisksd
CWD  2083: /home/ruut
EXE  2083: /usr/bin/nautilus
CWD  2084: /home/ruut
EXE  2084: /usr/bin/nautilus
CWD  2085: /
EXE  2085: /usr/lib/evolution/evolution-calendar-factory
CWD  2086: /
EXE  2086: /usr/lib/evolution/evolution-calendar-factory
CWD  2087: /
EXE  2087: /usr/lib/evolution/evolution-calendar-factory
CWD  2095: /
EXE  2095: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2096: /
EXE  2096: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2097: /
EXE  2097: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2098: /
EXE  2098: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2101: /
EXE  2101: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2102: /
EXE  2102: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2107: /
EXE  2107: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2108: /
EXE  2108: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2109: /
EXE  2109: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2110: /
EXE  2110: /usr/lib/evolution/evolution-calendar-factory-subprocess
CWD  2117: /
EXE  2117: /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
CWD  2119: /
EXE  2119: /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
CWD  2123: /
EXE  2123: /usr/lib/evolution/evolution-addressbook-factory
CWD  2126: /
EXE  2126: /usr/lib/gvfs/gvfs-afc-volume-monitor
CWD  2127: /
EXE  2127: /usr/lib/gvfs/gvfs-afc-volume-monitor
CWD  2129: /
EXE  2129: /usr/lib/gvfs/gvfs-afc-volume-monitor
CWD  2132: /
EXE  2132: /usr/lib/gvfs/gvfs-mtp-volume-monitor
CWD  2134: /
EXE  2134: /usr/lib/gvfs/gvfs-mtp-volume-monitor
CWD  2135: /home/ruut
EXE  2135: /usr/bin/nautilus
CWD  2141: /
EXE  2141: /usr/lib/evolution/evolution-addressbook-factory
CWD  2142: /
EXE  2142: /usr/lib/evolution/evolution-addressbook-factory
CWD  2143: /
EXE  2143: /usr/lib/evolution/evolution-addressbook-factory
CWD  2147: /
EXE  2147: /usr/lib/evolution/evolution-addressbook-factory-subprocess
CWD  2149: /
EXE  2149: /usr/lib/evolution/evolution-addressbook-factory-subprocess
CWD  2150: /
EXE  2150: /usr/lib/evolution/evolution-addressbook-factory-subprocess
CWD  2151: /
EXE  2151: /usr/lib/evolution/evolution-addressbook-factory-subprocess
CWD  2176: /
EXE  2176: /usr/lib/gvfs/gvfsd-trash
CWD  2177: /
EXE  2177: /usr/lib/gvfs/gvfsd-trash
CWD  2183: /
EXE  2183: /usr/lib/gvfs/gvfsd-burn
CWD  2184: /
EXE  2184: /usr/lib/gvfs/gvfsd-burn
CWD  2198: /
EXE  2198: /usr/lib/gvfs/gvfsd-metadata
CWD  2199: /
EXE  2199: /usr/lib/gvfs/gvfsd-metadata
CWD  2206: /home/ruut
EXE  2206: /usr/bin/telepathy-indicator
CWD  2207: /home/ruut
EXE  2207: /usr/bin/telepathy-indicator
CWD  2208: /home/ruut
EXE  2208: /usr/bin/telepathy-indicator
CWD  2212: /
EXE  2212: /usr/lib/telepathy/mission-control-5
CWD  2213: /
EXE  2213: /usr/lib/telepathy/mission-control-5
CWD  2215: /
EXE  2215: /usr/lib/telepathy/mission-control-5
CWD  2229: /home/ruut
EXE  2229: /usr/bin/zeitgeist-datahub
CWD  2230: /home/ruut
EXE  2230: /usr/bin/zeitgeist-datahub
CWD  2231: /home/ruut
EXE  2231: /usr/bin/zeitgeist-datahub
CWD  2235: /
EXE  2235: /usr/bin/zeitgeist-daemon
CWD  2236: /
EXE  2236: /usr/bin/zeitgeist-daemon
CWD  2252: /home/ruut
EXE  2252: /usr/bin/zeitgeist-datahub
CWD  2258: /
EXE  2258: /usr/lib/x86_64-linux-gnu/zeitgeist-fts
CWD  2259: /
EXE  2259: /usr/lib/x86_64-linux-gnu/zeitgeist-fts
CWD  2295: /home/ruut
EXE  2295: /usr/bin/update-notifier
CWD  2296: /home/ruut
EXE  2296: /usr/bin/update-notifier
CWD  2297: /home/ruut
EXE  2297: /usr/bin/update-notifier
CWD  2402: /etc/gufw/app_profiles
EXE  2402: /usr/bin/python2.7
CWD  2403: /etc/gufw/app_profiles
EXE  2403: /usr/bin/python2.7
CWD  2431: /etc/gufw/app_profiles
EXE  2431: /usr/bin/python2.7
CWD  2432: /etc/gufw/app_profiles
EXE  2432: /usr/bin/python2.7
CWD  2433: /etc/gufw/app_profiles
EXE  2433: /usr/bin/python2.7
CWD  2439: /etc/gufw/app_profiles
EXE  2439: /usr/bin/python2.7
CWD  2440: /etc/gufw/app_profiles
EXE  2440: /usr/bin/python2.7
CWD  2527: /home/ruut
EXE  2527: /usr/bin/compiz
CWD  2528: /home/ruut
EXE  2528: /usr/bin/compiz
CWD  4506: /root
EXE  4506: /usr/bin/ettercap
CWD  4519: /root
EXE  4519: /usr/bin/ettercap
CWD  4520: /root
EXE  4520: /usr/bin/ettercap
CWD  4521: /root
EXE  4521: /usr/bin/ettercap
CWD  4563: /root
EXE  4563: /usr/bin/ettercap
CWD  4963: /home/ruut
EXE  4963: /usr/lib/gnome-terminal/gnome-terminal-server
CWD  4964: /home/ruut
EXE  4964: /usr/lib/gnome-terminal/gnome-terminal-server
CWD  4965: /home/ruut
EXE  4965: /usr/lib/gnome-terminal/gnome-terminal-server
CWD 12817: /
EXE 12817: /usr/lib/geoclue/geoclue-master
CWD 12818: /
EXE 12818: /usr/lib/geoclue/geoclue-master
CWD 12819: /
EXE 12819: /usr/lib/geoclue/geoclue-master
CWD 12822: /
EXE 12822: /usr/lib/x86_64-linux-gnu/ubuntu-geoip-provider
CWD 12823: /
EXE 12823: /usr/lib/x86_64-linux-gnu/ubuntu-geoip-provider
CWD 12824: /
EXE 12824: /usr/lib/x86_64-linux-gnu/ubuntu-geoip-provider
CWD 14767: /home/ruut
EXE 14767: /usr/lib/firefox/firefox
CWD 14768: /home/ruut
EXE 14768: /usr/lib/firefox/firefox
CWD 14769: /home/ruut
EXE 14769: /usr/lib/firefox/firefox
CWD 14770: /home/ruut
EXE 14770: /usr/lib/firefox/firefox
CWD 14771: /home/ruut
EXE 14771: /usr/lib/firefox/firefox
CWD 14772: /home/ruut
EXE 14772: /usr/lib/firefox/firefox
CWD 14773: /home/ruut
EXE 14773: /usr/lib/firefox/firefox
CWD 14776: /home/ruut
EXE 14776: /usr/lib/firefox/firefox
CWD 14777: /home/ruut
EXE 14777: /usr/lib/firefox/firefox
CWD 14778: /home/ruut
EXE 14778: /usr/lib/firefox/firefox
CWD 14779: /home/ruut
EXE 14779: /usr/lib/firefox/firefox
CWD 14780: /home/ruut
EXE 14780: /usr/lib/firefox/firefox
CWD 14781: /home/ruut
EXE 14781: /usr/lib/firefox/firefox
CWD 14782: /home/ruut
EXE 14782: /usr/lib/firefox/firefox
CWD 14783: /home/ruut
EXE 14783: /usr/lib/firefox/firefox
CWD 14787: /home/ruut
EXE 14787: /usr/lib/firefox/firefox
CWD 14788: /home/ruut
EXE 14788: /usr/lib/firefox/firefox
CWD 14791: /home/ruut
EXE 14791: /usr/lib/firefox/firefox
CWD 14792: /home/ruut
EXE 14792: /usr/lib/firefox/firefox
CWD 15770: /home/ruut
EXE 15770: /usr/lib/firefox/firefox
CWD 15773: /home/ruut
EXE 15773: /usr/lib/firefox/firefox
CWD 15774: /home/ruut
EXE 15774: /usr/lib/firefox/firefox
CWD 15775: /home/ruut
EXE 15775: /usr/lib/firefox/firefox
CWD 15778: /home/ruut
EXE 15778: /usr/lib/firefox/firefox
CWD 15779: /home/ruut
EXE 15779: /usr/lib/firefox/firefox
CWD 15782: /home/ruut
EXE 15782: /usr/lib/firefox/firefox
CWD 15783: /home/ruut
EXE 15783: /usr/lib/firefox/firefox
CWD 15784: /home/ruut
EXE 15784: /usr/lib/firefox/firefox
CWD 15785: /home/ruut
EXE 15785: /usr/lib/firefox/firefox
CWD 15786: /home/ruut
EXE 15786: /usr/lib/firefox/firefox
CWD 15787: /home/ruut
EXE 15787: /usr/lib/firefox/firefox
CWD 15788: /home/ruut
EXE 15788: /usr/lib/firefox/firefox
CWD 15807: /home/ruut
EXE 15807: /usr/lib/firefox/firefox
CWD 15829: /home/ruut
EXE 15829: /usr/lib/firefox/firefox
CWD 15832: /home/ruut
EXE 15832: /usr/lib/firefox/firefox
CWD 15834: /home/ruut
EXE 15834: /usr/lib/firefox/firefox
CWD 15835: /home/ruut
EXE 15835: /usr/lib/firefox/firefox
CWD 15836: /home/ruut
EXE 15836: /usr/lib/firefox/firefox
CWD 15837: /home/ruut
EXE 15837: /usr/lib/firefox/firefox
CWD 15838: /home/ruut
EXE 15838: /usr/lib/firefox/firefox
CWD 15841: /home/ruut
EXE 15841: /usr/lib/firefox/firefox
CWD 15864: /home/ruut
EXE 15864: /usr/lib/firefox/firefox
CWD 19105: /
EXE 19105: /usr/lib/x86_64-linux-gnu/notify-osd
CWD 19106: /
EXE 19106: /usr/lib/x86_64-linux-gnu/notify-osd
CWD 19107: /
EXE 19107: /usr/lib/x86_64-linux-gnu/notify-osd
CWD 20244: /home/ruut
EXE 20244: /usr/bin/compiz
CWD 20414: /
EXE 20414: /usr/bin/python3.4
CWD 20415: /
EXE 20415: /usr/bin/python3.4
CWD 20420: /home/ruut
EXE 20420: /usr/lib/x86_64-linux-gnu/indicator-session/indicator-session-service
CWD 20421: /home/ruut
EXE 20421: /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
CWD 20645: /home/ruut
EXE 20645: /usr/lib/firefox/firefox
PID 21226(/proc/21226): not in readdir output
PID 21226: not in ps output
CWD 21226: /home/ruut
EXE 21226: /bin/dash
PID 21227(/proc/21227): not in readdir output
PID 21227: not in ps output
CWD 21227: /home/ruut
EXE 21227: /bin/dash
PID 21228(/proc/21228): not in readdir output
PID 21228: not in ps output
CWD 21228: /home/ruut
EXE 21228: /bin/dash
CWD 21379: /root
EXE 21379: /usr/bin/ettercap
CWD 23091: /home/ruut
EXE 23091: /usr/lib/firefox/firefox
CWD 26116: /
EXE 26116: /usr/sbin/clamav-milter
CWD 26118: /
EXE 26118: /usr/sbin/clamav-milter
CWD 26119: /
EXE 26119: /usr/sbin/clamav-milter
CWD 26120: /
EXE 26120: /usr/sbin/clamav-milter
CWD 26121: /
EXE 26121: /usr/sbin/clamav-milter
CWD 26248: /proc
EXE 26248: /usr/lib/rtkit/rtkit-daemon
CWD 26249: /proc
EXE 26249: /usr/lib/rtkit/rtkit-daemon
CWD 26302: /
EXE 26302: /usr/lib/x86_64-linux-gnu/unity-scope-home/unity-scope-home
CWD 26304: /
EXE 26304: /usr/lib/x86_64-linux-gnu/unity-scope-home/unity-scope-home
CWD 26305: /
EXE 26305: /usr/lib/x86_64-linux-gnu/unity-scope-home/unity-scope-home
CWD 26315: /
EXE 26315: /usr/bin/unity-scope-loader
CWD 26316: /
EXE 26316: /usr/bin/unity-scope-loader
CWD 26317: /
EXE 26317: /usr/bin/unity-scope-loader
CWD 26444: /
EXE 26444: /usr/lib/x86_64-linux-gnu/unity-lens-files/unity-files-daemon
CWD 26445: /
EXE 26445: /usr/lib/x86_64-linux-gnu/unity-lens-files/unity-files-daemon
CWD 26446: /
EXE 26446: /usr/lib/x86_64-linux-gnu/unity-lens-files/unity-files-daemon
CWD 26448: /
EXE 26448: /usr/lib/x86_64-linux-gnu/unity-lens-files/unity-files-daemon
CWD 26449: /
EXE 26449: /usr/lib/x86_64-linux-gnu/unity-lens-files/unity-files-daemon
CWD 26835: /home/ruut
EXE 26835: /usr/lib/virtualbox/VirtualBox
CWD 26836: /home/ruut
EXE 26836: /usr/lib/virtualbox/VirtualBox
CWD 26837: /home/ruut
EXE 26837: /usr/lib/virtualbox/VirtualBox
CWD 26844: /home/ruut
EXE 26844: /usr/lib/virtualbox/VirtualBox
CWD 26845: /home/ruut
EXE 26845: /usr/lib/virtualbox/VirtualBox
CWD 26849: /home/ruut
EXE 26849: /usr/lib/virtualbox/VBoxSVC
CWD 26850: /home/ruut
EXE 26850: /usr/lib/virtualbox/VBoxSVC
CWD 26851: /home/ruut
EXE 26851: /usr/lib/virtualbox/VBoxSVC
CWD 26852: /home/ruut
EXE 26852: /usr/lib/virtualbox/VBoxSVC
CWD 26853: /home/ruut
EXE 26853: /usr/lib/virtualbox/VBoxSVC
CWD 26854: /home/ruut
EXE 26854: /usr/lib/virtualbox/VBoxSVC
CWD 26855: /home/ruut
EXE 26855: /usr/lib/virtualbox/VBoxSVC
CWD 26856: /home/ruut
EXE 26856: /usr/lib/virtualbox/VBoxSVC
CWD 26857: /home/ruut
EXE 26857: /usr/lib/virtualbox/VBoxSVC
CWD 26858: /home/ruut
EXE 26858: /usr/lib/virtualbox/VirtualBox
CWD 26864: /home/ruut
EXE 26864: /usr/lib/virtualbox/VBoxSVC
CWD 26865: /home/ruut
EXE 26865: /usr/lib/virtualbox/VBoxSVC
CWD 27039: /home/ruut
EXE 27039: /usr/bin/python2.7
CWD 27040: /home/ruut
EXE 27040: /usr/bin/python2.7
CWD 27041: /home/ruut
EXE 27041: /usr/bin/python2.7
CWD 27053: /
EXE 27053: /usr/bin/python3.4
CWD 27071: /home/ruut
EXE 27071: /usr/bin/python2.7
CWD 27072: /home/ruut
EXE 27072: /usr/bin/python2.7
CWD 27234: /home/ruut
EXE 27234: /usr/bin/python2.7
CWD 27235: /home/ruut
EXE 27235: /usr/bin/python2.7
CWD 32037: /
EXE 32037: /usr/lib/gvfs/gvfsd-http
CWD 32038: /
EXE 32038: /usr/lib/gvfs/gvfsd-http
CWD 32078: /
EXE 32078: /usr/lib/gvfs/gvfsd-http
You have    3 process hidden for readdir command
You have    3 process hidden for ps command
not found
###
### Output of: ./ifpromisc
###
lo: not promisc and no packet sniffer sockets
enp3s0: PACKET SNIFFER(/sbin/dhclient[1007], /usr/bin/ettercap[4481])
not infected
###
### Output of: ./chkwtmp -f /var/log/wtmp
###
not infected
not infected
###
### Output of: ./chklastlog  -f /var/log/wtmp -l /var/log/lastlog
###
user ruut deleted or never logged from lastlog!
user root deleted or never logged from lastlog!
 The tty of the following user process(es) were not found
 in /var/run/utmp !
! RUID          PID TTY    CMD
! root        1291 tty7  /usr/bin/X -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
chkutmp: nothing deleted
not infected


dennissteins 17.03.2016 02:23

auth.log...Auszug

Code:

Mar 17 00:11:36 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:11:36 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:11024:404799 (system bus name :1.118, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:11:49 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service ntp stop
Mar 17 00:11:49 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:11:49 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:11081:406152 (system bus name :1.119 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:11:49 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:11:49 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:11081:406152 (system bus name :1.119, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:11:56 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service list
Mar 17 00:11:56 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:11:56 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:12:02 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service
Mar 17 00:12:02 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:12:02 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:12:10 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service --status all
Mar 17 00:12:10 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:12:10 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:12:35 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service --status-all
Mar 17 00:12:35 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:12:36 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:13:11 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service cups stop
Mar 17 00:13:11 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:13:11 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:12006:414351 (system bus name :1.120 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:13:11 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:12006:414351 (system bus name :1.120, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:13:11 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:11993:414343 (system bus name :1.121 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:13:11 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:13:11 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:11993:414343 (system bus name :1.121, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:13:17 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:13:17 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:13:17 ruut-HP-280-G1-MT pkexec[12058]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 00:13:44 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service dns-clean reload
Mar 17 00:13:44 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:13:44 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:14:01 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service cups-browsed
Mar 17 00:14:01 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:14:01 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:14:19 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service cups-browsed
Mar 17 00:14:19 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:14:19 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:14:27 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service cups-browsed stop
Mar 17 00:14:27 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:14:27 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:12234:421984 (system bus name :1.127 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:14:27 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:14:27 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:12234:421984 (system bus name :1.127, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:15:00 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service bluetooth
Mar 17 00:15:00 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:15:00 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:15:13 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service bluetooth stop
Mar 17 00:15:13 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:15:13 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:12368:426585 (system bus name :1.128 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:15:13 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:15:13 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:12368:426585 (system bus name :1.128, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:15:51 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service checkroot-bootclean.sh stop
Mar 17 00:15:51 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:15:51 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:12476:430320 (system bus name :1.129 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:15:51 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:15:51 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:12476:430320 (system bus name :1.129, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:16:07 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service checkroot-bootclean.sh reload
Mar 17 00:16:07 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:16:07 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:16:36 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/service pure-ftpd stop
Mar 17 00:16:36 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:16:36 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:12610:434838 (system bus name :1.130 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:16:36 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:16:36 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:12610:434838 (system bus name :1.130, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:17:01 ruut-HP-280-G1-MT CRON[13971]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 17 00:17:01 ruut-HP-280-G1-MT CRON[13971]: pam_unix(cron:session): session closed for user root
Mar 17 00:19:04 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:15601:449644 (system bus name :1.134 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:19:04 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:15601:449644 (system bus name :1.134, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:19:42 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:20:01 ruut-HP-280-G1-MT CRON[17850]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 00:20:01 ruut-HP-280-G1-MT CRON[17850]: pam_unix(cron:session): session closed for user smmsp
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:17911:456818 (system bus name :1.142 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:17911:456818 (system bus name :1.142, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:17934:456843 (system bus name :1.143 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:17934:456843 (system bus name :1.143, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:17954:456857 (system bus name :1.144 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:17954:456857 (system bus name :1.144, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:16 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:17971:456910 (system bus name :1.145 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:17 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:17971:456910 (system bus name :1.145, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:47 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:18838:459917 (system bus name :1.146 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:47 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:18838:459917 (system bus name :1.146, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:18878:460452 (system bus name :1.147 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:18878:460452 (system bus name :1.147, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:18922:460481 (system bus name :1.148 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:18922:460481 (system bus name :1.148, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:18945:460498 (system bus name :1.149 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:52 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:18945:460498 (system bus name :1.149, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:20:54 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:18967:460648 (system bus name :1.151 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:20:54 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:18967:460648 (system bus name :1.151, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:22:17 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:22:17 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:22:17 ruut-HP-280-G1-MT pkexec[19187]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 00:22:46 ruut-HP-280-G1-MT polkit-agent-helper-1[19263]: pam_ecryptfs: pam_sm_authenticate: /home/ruut is already mounted
Mar 17 00:22:46 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:ruut to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:19257:471471 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:ruut)
Mar 17 00:22:46 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:22:46 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:22:46 ruut-HP-280-G1-MT pkexec[19259]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/sbin/synaptic]
Mar 17 00:23:45 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/17 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/apt-get install sqlite3+
Mar 17 00:23:45 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:23:45 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:23:55 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/1 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/apt-get install sqlite3
Mar 17 00:23:55 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:23:55 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:24:04 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/1 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/apt-get install sqlite3
Mar 17 00:24:04 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:24:16 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:24:57 ruut-HP-280-G1-MT polkit-agent-helper-1[20066]: pam_ecryptfs: pam_sm_authenticate: /home/ruut is already mounted
Mar 17 00:24:57 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:ruut to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:20060:484555 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:ruut)
Mar 17 00:24:57 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:24:57 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:24:57 ruut-HP-280-G1-MT pkexec[20062]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/sbin/synaptic]
Mar 17 00:25:01 ruut-HP-280-G1-MT CRON[20097]: pam_unix(cron:session): session opened for user daemon by (uid=0)
Mar 17 00:25:01 ruut-HP-280-G1-MT CRON[20097]: pam_unix(cron:session): session closed for user daemon
Mar 17 00:25:17 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:25:17 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:25:17 ruut-HP-280-G1-MT pkexec[20140]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 00:33:28 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:24973:536068 (system bus name :1.166 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:28 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:24973:536068 (system bus name :1.166, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:33:31 ruut-HP-280-G1-MT groupadd[25120]: group added to /etc/group: name=clamav, GID=135
Mar 17 00:33:32 ruut-HP-280-G1-MT groupadd[25120]: group added to /etc/gshadow: name=clamav
Mar 17 00:33:32 ruut-HP-280-G1-MT groupadd[25120]: new group: name=clamav, GID=135
Mar 17 00:33:32 ruut-HP-280-G1-MT useradd[25126]: new user: name=clamav, UID=125, GID=135, home=/var/lib/clamav, shell=/bin/false
Mar 17 00:33:32 ruut-HP-280-G1-MT chage[25133]: changed password expiry for clamav
Mar 17 00:33:32 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:25142:536506 (system bus name :1.167 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:32 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:25142:536506 (system bus name :1.167, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:33:35 ruut-HP-280-G1-MT useradd[25303]: new user: name=c-icap, UID=126, GID=65534, home=/var/run/c-icap, shell=/bin/false
Mar 17 00:33:36 ruut-HP-280-G1-MT usermod[25308]: change user 'c-icap' password
Mar 17 00:33:36 ruut-HP-280-G1-MT chage[25315]: changed password expiry for c-icap
Mar 17 00:33:36 ruut-HP-280-G1-MT groupadd[25319]: group added to /etc/group: name=c-icap, GID=136
Mar 17 00:33:36 ruut-HP-280-G1-MT groupadd[25319]: group added to /etc/gshadow: name=c-icap
Mar 17 00:33:36 ruut-HP-280-G1-MT groupadd[25319]: new group: name=c-icap, GID=136
Mar 17 00:33:36 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:25326:536900 (system bus name :1.168 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:36 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:25326:536900 (system bus name :1.168, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:33:36 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:25363:536913 (system bus name :1.169 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:37 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:25363:536913 (system bus name :1.169, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:33:37 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:25386:536926 (system bus name :1.170 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:37 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:25386:536926 (system bus name :1.170, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:33:47 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:26170:537929 (system bus name :1.171 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:33:47 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:26170:537929 (system bus name :1.171, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:34:55 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 00:34:55 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 00:34:55 ruut-HP-280-G1-MT pkexec[26396]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 00:36:16 ruut-HP-280-G1-MT userhelper[26601]: pam_unix(passwd:chauthtok): authentication failure; logname= uid=1000 euid=0 tty= ruser=ruut rhost=  user=ruut
Mar 17 00:36:39 ruut-HP-280-G1-MT userhelper[26647]: pam_unix(passwd:chauthtok): authentication failure; logname= uid=1000 euid=0 tty= ruser=ruut rhost=  user=ruut
Mar 17 00:36:56 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/1 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/passwd root
Mar 17 00:36:56 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:36:56 ruut-HP-280-G1-MT passwd[26690]: pam_ecryptfs: PAM passphrase change module retrieved a NULL passphrase; nothing to do
Mar 17 00:37:11 ruut-HP-280-G1-MT passwd[26690]: pam_unix(passwd:chauthtok): password changed for root
Mar 17 00:37:11 ruut-HP-280-G1-MT passwd[26690]: gkr-pam: couldn't update the login keyring password: no old password was entered
Mar 17 00:37:11 ruut-HP-280-G1-MT passwd[26690]: pam_ecryptfs: Passphrase file wrapped
Mar 17 00:37:11 ruut-HP-280-G1-MT passwd[26690]: pam_ecryptfs: PAM passphrase change module retrieved at least one NULL passphrase; nothing to do
Mar 17 00:37:11 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:37:26 ruut-HP-280-G1-MT userhelper[26726]: pam_unix(passwd:chauthtok): authentication failure; logname= uid=1000 euid=0 tty= ruser=ruut rhost=  user=ruut
Mar 17 00:39:48 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/1 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/chkrootkit
Mar 17 00:39:48 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:40:01 ruut-HP-280-G1-MT CRON[27754]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 00:40:02 ruut-HP-280-G1-MT CRON[27754]: pam_unix(cron:session): session closed for user smmsp
Mar 17 00:40:08 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:40:52 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/13 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/rkhunter -c
Mar 17 00:40:52 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:40:58 ruut-HP-280-G1-MT Rootkit Hunter: Rootkit hunter check started (version 1.4.2)
Mar 17 00:44:43 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/12 ; PWD=/home/ruut ; USER=root ; COMMAND=/bin/bash
Mar 17 00:44:43 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:45:01 ruut-HP-280-G1-MT CRON[24645]: pam_unix(cron:session): session opened for user clamav by (uid=0)
Mar 17 00:45:29 ruut-HP-280-G1-MT polkit-agent-helper-1[28616]: pam_ecryptfs: pam_sm_authenticate: /home/ruut is already mounted
Mar 17 00:45:29 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:ruut to gain TEMPORARY authorization for action org.debian.apt.install-file for system-bus-name::1.180 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:ruut)
Mar 17 00:46:00 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:7551:611224 (system bus name :1.188 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:46:00 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:7551:611224 (system bus name :1.188, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:46:01 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:7572:611323 (system bus name :1.189 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:46:01 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:7572:611323 (system bus name :1.189, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:46:09 ruut-HP-280-G1-MT polkitd(authority=local): Registered Authentication Agent for unix-process:7612:612197 (system bus name :1.190 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Mar 17 00:46:10 ruut-HP-280-G1-MT polkitd(authority=local): Unregistered Authentication Agent for unix-process:7612:612197 (system bus name :1.190, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Mar 17 00:48:22 ruut-HP-280-G1-MT CRON[24645]: pam_unix(cron:session): session closed for user clamav
Mar 17 00:50:06 ruut-HP-280-G1-MT sudo:    root : TTY=pts/12 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/geany /var/mail/root
Mar 17 00:50:06 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:51:49 ruut-HP-280-G1-MT Rootkit Hunter: Scanning took 10 minutes and 49 seconds
Mar 17 00:51:49 ruut-HP-280-G1-MT Rootkit Hunter: Please inspect this machine, because it may be infected.
Mar 17 00:51:49 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:52:24 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/13 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/tiger
Mar 17 00:52:24 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:52:44 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/18 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/chkrootkit -x
Mar 17 00:52:44 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 00:55:01 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:55:01 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:55:33 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 00:56:13 ruut-HP-280-G1-MT sudo: pam_unix(sudo:auth): authentication failure; logname=ruut uid=1000 euid=0 tty=/dev/pts/12 ruser=ruut rhost=  user=ruut
Mar 17 00:58:32 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 01:00:01 ruut-HP-280-G1-MT CRON[17376]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 17 01:00:01 ruut-HP-280-G1-MT CRON[17377]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 01:00:01 ruut-HP-280-G1-MT CRON[17377]: pam_unix(cron:session): session closed for user smmsp
Mar 17 01:00:03 ruut-HP-280-G1-MT CRON[17376]: pam_unix(cron:session): session closed for user root
Mar 17 01:01:32 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 01:01:32 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 01:01:32 ruut-HP-280-G1-MT pkexec[17590]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 01:02:31 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/12 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-client
Mar 17 01:02:31 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 01:02:36 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 01:06:30 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/12 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/tcpdump -Annvvs 1500 -i any udp and dst port 53
Mar 17 01:06:30 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 01:11:47 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action org.debian.apt.install-file for system-bus-name::1.180 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:ruut)
Mar 17 01:17:01 ruut-HP-280-G1-MT CRON[18784]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 17 01:17:01 ruut-HP-280-G1-MT CRON[18784]: pam_unix(cron:session): session closed for user root
Mar 17 01:17:45 ruut-HP-280-G1-MT polkit-agent-helper-1[18836]: pam_ecryptfs: pam_sm_authenticate: /home/ruut is already mounted
Mar 17 01:17:46 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:ruut to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.180 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:ruut)
Mar 17 01:18:42 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/19 ; PWD=/home/ruut ; USER=root ; COMMAND=/bin/bash
Mar 17 01:18:42 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 01:20:01 ruut-HP-280-G1-MT CRON[19181]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 01:20:02 ruut-HP-280-G1-MT CRON[19181]: pam_unix(cron:session): session closed for user smmsp
Mar 17 01:22:26 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 01:22:26 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 01:22:26 ruut-HP-280-G1-MT pkexec[19423]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 01:25:02 ruut-HP-280-G1-MT CRON[19634]: pam_unix(cron:session): session opened for user daemon by (uid=0)
Mar 17 01:25:03 ruut-HP-280-G1-MT CRON[19634]: pam_unix(cron:session): session closed for user daemon
Mar 17 01:35:52 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/21 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/sbin/chkrootkit
Mar 17 01:35:52 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 01:36:12 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 01:40:01 ruut-HP-280-G1-MT CRON[22824]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 01:40:02 ruut-HP-280-G1-MT CRON[22824]: pam_unix(cron:session): session closed for user smmsp
Mar 17 01:41:59 ruut-HP-280-G1-MT polkit-agent-helper-1[22953]: pam_unix(polkit-1:auth): authentication failure; logname= uid=1000 euid=0 tty= ruser=ruut rhost=  user=ruut
Mar 17 01:42:04 ruut-HP-280-G1-MT polkit-agent-helper-1[22975]: pam_ecryptfs: pam_sm_authenticate: /home/ruut is already mounted
Mar 17 01:42:04 ruut-HP-280-G1-MT polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:ruut to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.180 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:ruut)
Mar 17 01:45:01 ruut-HP-280-G1-MT CRON[26066]: pam_unix(cron:session): session opened for user clamav by (uid=0)
Mar 17 01:47:57 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/21 ; PWD=/home/ruut ; USER=root ; COMMAND=/bin/bash
Mar 17 01:47:57 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)
Mar 17 01:49:48 ruut-HP-280-G1-MT CRON[26066]: pam_unix(cron:session): session closed for user clamav
Mar 17 01:52:42 ruut-HP-280-G1-MT pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Mar 17 01:52:42 ruut-HP-280-G1-MT pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Mar 17 01:52:42 ruut-HP-280-G1-MT pkexec[26825]: ruut: Executing command [USER=root] [TTY=unknown] [CWD=/home/ruut] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Mar 17 02:00:01 ruut-HP-280-G1-MT CRON[27331]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 17 02:00:01 ruut-HP-280-G1-MT CRON[27332]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Mar 17 02:00:01 ruut-HP-280-G1-MT CRON[27332]: pam_unix(cron:session): session closed for user smmsp
Mar 17 02:00:03 ruut-HP-280-G1-MT CRON[27331]: pam_unix(cron:session): session closed for user root
Mar 17 02:08:15 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session closed for user root
Mar 17 02:08:43 ruut-HP-280-G1-MT sudo:    ruut : TTY=pts/13 ; PWD=/home/ruut ; USER=root ; COMMAND=/usr/bin/nautilus
Mar 17 02:08:44 ruut-HP-280-G1-MT sudo: pam_unix(sudo:session): session opened for user root by ruut(uid=0)

Verdacht? Ebury?

Code:

ruut@ruut-HP-280-G1-MT:~$ ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo "System clean" || echo "System infected"
System infected
ruut@ruut-HP-280-G1-MT:~$  2>&1 | grep -e illegal -e unknown > /dev/null

Zitat:

ruut@ruut-HP-280-G1-MT:~$ sudo tcpdump -Annvvs 1500 -i any udp and dst port 53
[sudo] password for ruut:
tcpdump: listening on any, link-type LINUX_SLL (Linux cooked), capture size 1500 bytes
01:06:37.305794 IP (tos 0x0, ttl 64, id 30384, offset 0, flags [DF], proto UDP (17), length 65)
127.0.0.1.52743 > 127.0.1.1.53: [bad udp cksum 0xff40 -> 0x72bb!] 13866+ A? blog.ip-projects.de. (37)
E..Av.@.@..............5.-.@6*...........blog.ip-projects.de.....
01:06:37.307828 IP (tos 0x0, ttl 64, id 19227, offset 0, flags [DF], proto UDP (17), length 65)
192.168.178.20.52277 > 192.168.178.1.53: [udp sum ok] 28920+ A? blog.ip-projects.de. (37)
E..AK.@.@.
*.........5.5.-SZp............blog.ip-projects.de.....
01:07:25.053540 IP (tos 0x0, ttl 64, id 35512, offset 0, flags [DF], proto UDP (17), length 65)
127.0.0.1.39834 > 127.0.1.1.53: [bad udp cksum 0xff40 -> 0x70a1!] 27313+ A? blog.ip-projects.de. (37)
E..A..@.@..............5.-.@j............blog.ip-projects.de.....
01:07:25.053771 IP (tos 0x0, ttl 64, id 30654, offset 0, flags [DF], proto UDP (17), length 65)
192.168.178.20.30394 > 192.168.178.1.53: [udp sum ok] 38044+ A? blog.ip-projects.de. (37)
E..Aw.@.@...........v..5.-.1.............blog.ip-projects.de.....
01:07:36.804357 IP (tos 0x0, ttl 64, id 37662, offset 0, flags [DF], proto UDP (17), length 73)
127.0.0.1.44224 > 127.0.1.1.53: [bad udp cksum 0xff48 -> 0x0a64!] 31408+ A? shavar.services.mozilla.com. (45)
E..I..@.@..............5.5.Hz............shavar.services.mozilla.com.....
01:07:36.804534 IP (tos 0x0, ttl 64, id 30978, offset 0, flags [DF], proto UDP (17), length 73)
192.168.178.20.28316 > 192.168.178.1.53: [udp sum ok] 5742+ A? shavar.services.mozilla.com. (45)
E..Iy.@.@..:........n..5.5.e.n...........shavar.services.mozilla.com.....
01:08:05.393064 IP (tos 0x0, ttl 64, id 38431, offset 0, flags [DF], proto UDP (17), length 59)
127.0.0.1.51009 > 127.0.1.1.53: [bad udp cksum 0xff3a -> 0xa444!] 32223+ A? bitbucket.org. (31)
E..;..@.@............A.5.'.:}........... bitbucket.org.....
01:08:05.393148 IP (tos 0x0, ttl 64, id 33243, offset 0, flags [DF], proto UDP (17), length 59)
192.168.178.20.46095 > 192.168.178.1.53: [udp sum ok] 38909+ A? bitbucket.org. (31)
E..;..@.@..o...........5.'.............. bitbucket.org.....

Ebury, ja, auch...

Dante12 17.03.2016 03:41

Du schmeisst hier mit Listen um dich

Zitat:

Searching for Linux/Ebury - Operation Windigo ssh... Possible Linux/Ebury - Operation Windigo installetd
Erklär mir doch mal wie du herausfinden kannst ob der Ebury Backdoor aktiv ist...

stephan65 17.03.2016 09:52

Da der "Virus" scheinbar:crazy: im BIOS sitzt, könnte man doch einfach das komplette Mainboard austauschen.

cosinus 17.03.2016 09:54

Zitat:

Zitat von stephan65 (Beitrag 1571194)
Da der "Virus" scheinbar:crazy: im BIOS sitzt, könnte man doch einfach das komplette Mainboard austauschen.

Vllt nutzt er auch Metallteile des Gehäuses als Cache...also besser auch das Gehäuse tauschen :lach:

stephan65 17.03.2016 09:59

Oder gleich den User.... :headbang:

purzelbär 17.03.2016 11:29

Zitat:

Zitat von stephan65 (Beitrag 1571194)
Da der "Virus" scheinbar:crazy: im BIOS sitzt, könnte man doch einfach das komplette Mainboard austauschen.

Könnte man in dem Fall nicht eine womöglich andere, neuere BIOS Version für das Mainboard installieren nachdem die bisherige gelöscht wurde?

stephan65 17.03.2016 11:37

Denke, dass das nichts bringt. Der Bios-Chip ist von der Hardware her verseucht. Ausserdem könnten auch der Onboard Grafik- und der LANChip verseucht sein. Nicht zu vergessen das Netzteil und die ganzen Ports (USB, PS2...). Ich denke da hilft nur ein Umstieg auf:

http://images.google.de/imgres?imgur...3qA7QQ9QEINjAC

purzelbär 17.03.2016 11:40

Okay, Danke für die Erklärung stephan65:dankeschoen: dann bräuchte er wahrscheinlich auch andere RAM Riegel? und was ist mit dem Prozessor? gehört der dann auch ausgetauscht?
Sein vermeintliches Problem ist ja auch das wenn ich das richtig verstanden habe das die Symtome nicht nur auf einem PC auftreten sondern auf verschiedenen PC's. Deshalb dachte ich eher wenn da wirklich was ist, das dann ein Hacker Zugriff auf sein Netzwerk hat. Wenn wirklich bei ihm etwas ist in Richtung Rootkit was ja noch nicht geklärt ist.

cosinus 17.03.2016 11:41

Und alle Kabel am besten auch austauschen, da ist das Rootkit ja auch druchgegangen ;)
Und vergesst das Netzteil nicht! :D das Rootkit wurde von diesem schließlich mit Strom versorgt :blabla:

stephan65 17.03.2016 11:42

Ja klar. Wobei das Ganze nichts bringt, wenn die ganzen Teile bereits bei der Herstellung verseucht sind....

_sTaNlEy_ 17.03.2016 11:46

Falls WLAN eingesetzt wurde, hat das für das Haus bzw. die Wohnung dann auch fatale Konsequenzen?:zunge:

stephan65 17.03.2016 11:48

Und man müsste auch in die Bergwerke in denen die Rohstoffe für die Platinen abgebaut werden. Oh genügt auch nicht. Die Metalle entstehen ja bei einer Super-Nova Explosion. Oder vielleicht sogar beim Urknall. Tja, da hilft wohl gar nix mehr...

purzelbär 17.03.2016 11:55

Ihr seid ja fies:eek::lach:

Zitat:

Oh genügt auch nicht. Die Metalle entstehen ja bei einer Super-Nova Explosion. Oder vielleicht sogar beim Urknall. Tja, da hilft wohl gar nix mehr...
Menno dann ist ja nicht einmal unser Ausserirdischer cosinus davor sicher weil es ja im ganzen Universum inkl. dem Heimatplaneten von cosinus statt gefunden hat:applaus:Also cosinus, mach das Fenster auf und schmeiß deinen PC runter auf die Strasse und schau vorher das unten keiner in dem Moment vorbei läuft:blabla:

Dante12 17.03.2016 12:06

Code:

Und alle Kabel am besten auch austauschen, da ist das Rootkit ja auch druchgegangen
Und vergesst das Netzteil nicht!  das Rootkit wurde von diesem schließlich mit Strom versorgt

= NSA :D

stephan65 17.03.2016 12:07

Oh mann, vielleicht ist das Ganze auch von einer Macht geplant, die in einem Paralleluniversum lebt und durch den Rechner Zugang in unsere Welt sucht. Wir verstehen nur deren Botschaft nicht...:taenzer:

cosinus 17.03.2016 12:11

Das kommt von Spezies 8472 aus dem flüssigen Raum :rofl:

stephan65 17.03.2016 12:31

Mal Spaß beiseite. Hat es schon mal einen BIOS-Trojaner gegeben ?

Deathkid535 17.03.2016 12:35

Im Labor, ja. Aber im virtuellen Wildlife wirst du keinen finden.

stephan65 17.03.2016 12:38

Entschuldige die Nachfrage. Warum nicht ? Ist das schwer zu programieren ? Oder was sind die Gründe dafür ?

purzelbär 17.03.2016 13:03

Zitat:

Zitat von cosinus (Beitrag 1571251)
Das kommt von Spezies 8472 aus dem flüssigen Raum :rofl:

Wusste ichs doch das du dich mit denen angelegt hast:nono: und die dich jetzt durchs Universum jagen um dich endlich pulverisieren zu können:lach:

Bootsektor 17.03.2016 21:14

Nunja....

BIOS-Rootkit LightEater: In den dunklen Ecken abseits des Betriebssystems

purzelbär 17.03.2016 22:02

Zitat:

Nunja....

BIOS-Rootkit LightEater: In den dunklen Ecken abseits des Betriebssystems
__________________
Grüße

Sandra

stolzes Mitglied von UNITE

Bootsektor, das liest sich ja wie ein Gruselroman von allerfeinster Güte:wtf:und wenn es das im Darknet gibt, kann ich mir gut vorstellen das sich Hacker das besorgen und der TE einem solchen Angriff erlegen sein könnte.

cosinus 18.03.2016 00:05

Da steht nur was von proof-of-concept. Aber dass sowas möglich ist, war ja schon bei UEFI sowieso schon vorher klar und auch bei BIOS - ein Jumper, der nur das BIOS hardwareseitig auf readonly stellt würde sowas schnell zunichte machen.

Und wie sind auch schon wieder irgendwie bei schraubers Aussage, entweder war da was auf der Platte oder irgendwo in einem flashbaren Chip auf dem Rechner.

milchkeks 24.03.2016 12:58

Liebes "Kompetenzteam", auch wenn der O-Poster keine wirkliche Ahnung hat, was los ist, würde ich doch euch als Experten um etwas mehr Professionalität bitten, anstatt hier wild herumzubashen.

Es gibt ein handfestes Indiz, dass etwas faul sein KÖNNTE: den Hinweis auf eine "Ebury"-Infektion.

Also bitte - HIERZU brauchbare Beiträge, oder eben keine, wenn sonst niemand etwas damit anfangen kann, höchstens den Hinweis an Dennis, er möge es bitte unterlassen, zusammenhangslos ellenlange Logs herumzuposten.

Alles andere spart euch bitte dann auch, Bashing-Beiträge sind ebensowenig hilfreich.

Und ja, es gibt Bootkits auf BIOS-Basis, lt. Blackhat-Konferenz u. a. Außerdem wird heute praktisch jedes Notebook ab Werk mit einem BIOS-Bootkit von Absolute Software ausgeliefert (Computrace), der vermutlich auf Intel's ME-Modul aufsetzt - firmiert dann nur offiziell als "Diebstahlschutz".

cosinus 24.03.2016 13:21

Zitat:

Zitat von milchkeks (Beitrag 1573292)
Es gibt ein handfestes Indiz, dass etwas faul sein KÖNNTE: den Hinweis auf eine "Ebury"-Infektion.

Hättest du vllt auch die Güte auf diese Stelle genau hinzuweisen? :rolleyes:

Zitat:

Zitat von milchkeks (Beitrag 1573292)
Also bitte - HIERZU brauchbare Beiträge,

So brauchbar wie deiner jetzt? :kaffee:

Zitat:

Zitat von milchkeks (Beitrag 1573292)
Und ja, es gibt Bootkits auf BIOS-Basis, lt. Blackhat-Konferenz u. a. Außerdem wird heute praktisch jedes Notebook ab Werk mit einem BIOS-Bootkit von Absolute Software ausgeliefert (Computrace), der vermutlich auf Intel's ME-Modul aufsetzt - firmiert dann nur offiziell als "Diebstahlschutz".

Nur weil es so etwas gibt heißt das nicht, dass dieser Fall auch wahrscheinlich ist. Aber wie gesagt, erleuchte uns doch mal indem du relevante Stellen zeigst.

milchkeks 24.03.2016 17:34

http://www.trojaner-board.de/176707-...ml#post1571169

Das habt ihr ja selbst gelesen, seid aber leider nicht näher darauf eingegangen, was nun mit dieser Meldung anzufangen sei.

Die zweite Frage war, ob es hypothetische oder reale BIOS-Bootkits gibt, und die kann eindeutig mit ja beantwortet werden, wenn man die Funktionalität und Verhaltensweise von Computrace + UEFI + Windows betrachtet.

Hier handelt es sich nur um eine kommerzielle Variante. Proof-of-Concepts gibt es schon etliche andere, wie ihr ja bereits selbst geschrieben habt, und wiederum andere könnten z. B. von staatlicher, bzw. krimineller Seite kommen, s. Hacking Team, Bundestrojaner usw.

Dante12 24.03.2016 19:48

Zitat:

Es gibt ein handfestes Indiz, dass etwas faul sein KÖNNTE: den Hinweis auf eine "Ebury"-Infektion.
Gibt es nicht!
Ein simple SSH -G Funktion gibt nämlich folgendes aus:
Zitat:

Causes ssh to print its configuration after evaluating Host and Match blocks and exit.
Bei den oben erwähnten Test kann ich nämlich reinschreiben was ich will es kommt immer die letzte Meldung heraus. Mit dieser Methode haben sich selbst namhafte AV-Hersteller ins Bein geschossen.

Eine einfache Überprüfung des Shared Memories
Code:

ipcs -m
und die Ausgabe (oder ähnliche Ausgabe) wie
Zitat:

key shmid owner perms bytes nattch
0x000006e0 65538 root 666 3283128 0
wäre schon ein sehr konkreter Hinweis einer Infektion.

Bedenken sollte man auch das Ebury über die Versionssprünge immer andere Wege für eine Infektion sucht, zum Beispiel frühere Versionen <1.5 ergeben folgende Ausgabe:
Code:

key        shmid      owner    perms      bytes      nattch
0x0000091a    0      root      600        463084    0

Ein Prüfen der Checksummen auf ein Debian Linux-System
Code:

debsums openssh-server
Alles andere als ein OK ist ein Indiz für manipulierte Dateien und auf Red Hat Systemen (Beispiel)

Code:

rpm -Vv keyutils-libs-1.2-1.el5
Auf der linken Seite der Ausgabe dürfen ausser den Punkten nichts zu sehen sein

Code:

........    /lib/libkeyutils-1.2.so
S.2.....    /lib/libkeyutils.so.1
A.5.....    /usr/share/doc/keyutils-libs-1.2
........  d /usr/share/doc/keyutils-libs-1.2/LICENCE.LGPL

Das ist ein infiziertes System.

Weder chrootkit noch ClamAV sind zurzeit in der Lage Ebury eindeutig zu Identifizieren. Von den anderen Herstellern mag ich lieber nicht reden.

Das Abschalten und neu Aufsätzen des Servers ist die einzige Möglichkeit Ebury vollständig zu eliminieren.

Tipp: Googled nach Windigo

So weit mein Kenntnisstand ....

LfAnswers 24.03.2016 20:04

Ich finde es ganz interessant das hier zu verfolgen, ich würde wahnsinnig werden, wenn ich das auf den Screenshots auf der ersten Seite hätte, aber jeder Experte sagt hier, dass alles in Ordnung ist. Ich sollte mich vielleicht länger hier im Forum rumtreiben um zu lernen und weniger ängstlich zu werden.

purzelbär 24.03.2016 20:21

Falls Interesse besteht das zu lesen, es gibt wohl Schadsoftware(in dem Fall ein Erpessungstrojaner)die sich im MBR der Festplatte einnisten kann wenn ich das beim mitlesen richtig interpretiert habe in dem Thread: http://www.computerbase.de/forum/showthread.php?t=1571643

cosinus 25.03.2016 14:59

Zitat:

Zitat von milchkeks (Beitrag 1573356)
http://www.trojaner-board.de/176707-...ml#post1571169

Das habt ihr ja selbst gelesen, seid aber leider nicht näher darauf eingegangen, was nun mit dieser Meldung anzufangen sei.

Die zweite Frage war, ob es hypothetische oder reale BIOS-Bootkits gibt, und die kann eindeutig mit ja beantwortet werden, wenn man die Funktionalität und Verhaltensweise von Computrace + UEFI + Windows betrachtet.

Hier handelt es sich nur um eine kommerzielle Variante. Proof-of-Concepts gibt es schon etliche andere, wie ihr ja bereits selbst geschrieben habt, und wiederum andere könnten z. B. von staatlicher, bzw. krimineller Seite kommen, s. Hacking Team, Bundestrojaner usw.

Kannst du jetzt auf diese Stelle hinweisen und willst du hier nur rumschwätzen? :wtf:

Dante12 25.03.2016 16:59

Hacking Team verwendet UEFI-Rootkit

BIOS and Secure Boot Attacks Uncovered (PDF)

Jede Software oder Funktion die über das laufende OS Zugriff auf das BIOS hat kann kompromittiert werden.

A Real SMM Rootkit: Reversing and Hooking BIOS SMI Handlers

EDIT: Im Augenblick sieht es hier etwas durcheinander aus. Kein Verweis auf Inhalte aus den Logs. Wäre schön wenn wir uns darauf konzentrieren könnten, allerdings hat der TO bis auf seine Logs nichts großartig dazu geschrieben :aufsmaul:
Sonst könnten wir hier weiter über allgemeine Inhalte diskutieren die aber der Funktion dieses Forums in Widerspruch stehen.
.

milchkeks 26.03.2016 00:44

Thanks Dante12,

für die Einblicke, genau so etwas hatte ich mir gewünscht :)

cosinus 27.03.2016 00:51

Zitat:

Zitat von milchkeks (Beitrag 1573887)
Thanks Dante12,

für die Einblicke, genau so etwas hatte ich mir gewünscht :)

Von dir wünschen wir uns leider immer noch die konkreten Sachen. Oder sollen wir das als Dünnschiss werten? :D

W_Dackel 27.03.2016 11:37

Milchkeks hat in einem Punkt schon Recht: die meisten Antworten hier sind nicht geeignet den Threadersteller zu beruhigen.

@Dennissteins: statt über theoretische Gefahren zu diskutieren sollten wir uns einfach mal in die Rolle der Trojaner/ Rootkitschreiber versetzen.

Warum schreibt jemand so etwas ?

1. Kommerzielles Interesse (Spam, Krypto, DDOS, gekaperte Rechner vermieten).

Da geht es schlichtweg um Gewinne, also mit möglichst wenig Aufwand viele Rechner zu kapern. Da im Web Millionen von schlecht gesicherten Windows Kisten unterwegs sind wird sich ein Profi nie die Mühe machen ein Linux (1,8% Marktanteil) oder ein BIOS ( noch geringerer Martkanteil da jeder Virus direkt auf eine Variante eines bestimmten BIOS aufsetzen muss) zu infizieren- zu viel Aufwand zu wenig Gewinn.

2. Ein Geheimdienst ist hinter dir her. Sollte das so sein ist ein Forum der falsche Weg, dann musst du dich an Profis aus der Geheimdienst-Szene wenden. So etwas wie Stuxnet etc. entdeckt man nicht mit AV Programmen oder Rootkit-Hunter Shellskripten.


Da 2. unwahrscheinlich ist und 1. kaum über BIOS oder Linux geht wirst du hier hochgenommen. Bei den Ubuntu Logs in die ich reingeguckt habe fand ich auch nichts Auffälliges. Allerdings muss ich zugeben dass ich selbst nach ~15 Jahren Linux nicht sicher bin ob ich ein Rootkit fände, daher finde ich deinen Anspruch das nach einem halben Jahr können zu wollen etwas ambitioniert: du kennst das System einfach nicht gut genug um zu erkennen welche Meldungen auf ernste Anomalien hindeuten. Außerdem würde ein Geheimdienst-Angreifer dafür sorgen dass genau diese Meldungen nicht im System Log landen. Zumal dein Ubuntu bestimmt nicht mehr das traditionelle System Log verwendet (zumindest weist eine der Fehlermeldungen darauf hin) sondern bestimmt systemctl.

Beruhigt ?

Zum Win 10 kann ich nichts sagen, da solltest du vielleicht einfach mal die typischen Foren-Tools drüberlaufen lassen und einen Thread aufmachen. Nicht Win und Linux vermischen.


Zu der Ubunut Ebury Warnung:

http://ubuntuforums.org/showthread.php?t=2291968

Die Rootkit Skripte warnen lieber einmal zu viel als zu wenig, und produzieren daher oft Fehlalarme. Daher sollte man solche Warnungen googlen und kommt dann auf Seiten mit weiteren Hinweisen (z.B. andere Desktopsysteme auf denen diese Warnung als Fehlerhafte Warnung kam).

Wenn du sicher gehen willst lies das hier durch und führe die Tests durch:

https://www.cert-bund.de/ebury-faq

.. wie ein Forenteilnehmer oben schon als Beispiel brachte.


Bei RK Suche musst du also Schritt für Schritt und mit Systematik vorgehen, außerdem die Logik nicht außen vor lassen: Ebury würde dein Linux infizieren, weder Win10 noch BIOS wären betroffen. Außerdem ist eine Infektion von Desktop Systemen ziemlich unwahrscheinlich, da müssen die Angreifer erst mal durch deinen Internet Router durch. Solange du also nicht Binaries aus zweifelhaften Quellen installierst ist das extrem unwahrscheinlich.

milchkeks 27.03.2016 17:03

@W_Dackel:
UEFI bedeutet ja "Unified Extensible Firmware Interface", d. h. es baut auf genormte Schnittstellen auf, und ist modular konzipiert, wodurch es eben weitaus einfacher ist, als früher, für unterschiedliche Hardware Firmware-Schadcode zu schreiben, der sich als Modul in die Firmware einklinkt. Zumal wir es im Grunde nur mit 2 Anbietern von Firmware zu tun haben. Außerdem verwenden diese Anbieter proprietäre Module weiterer Hersteller, wie Intel's ME, welche wiederum API's anbieten, an denen auch Schadcode andocken kann.

Dann ist es wohl auch so, dass sich UEFI-Schadcode, einmal für eine Plattform etabliert, im Grunde völlig unabhängig von dem aufsetzenden OS (und von diesem nicht kontrollierbar) einsetzen lässt.
Dank der grenzenlosen Ignoranz der Hardwarehersteller, die selbst noch den Schreibschutz-Jumper und Flash-Stecksockel auf den Mainboards einsparen, ist man spätestens seit UEFI der Gefahr einer irreversiblen und kaum auffindbaren Infektion der Hardware ausgesetzt - q. e. d.

Die Investition in den Entwicklungsaufwand lohnt sich also.

Ich sehe daher die Gefahr einer neuen Welle von Bootkit-Trojanern in naher Zukunft (abseits der bereits erwähnten ohnehin schon ab Werk vorhandenen), gegen die wir ziemlich wehrlos sein werden, als durchaus real, bzw. wahrscheinlich an. Man muss sich dazu nur den proprietären Charakter eines UEFI-Stacks samt Hardwaretreibern, nebst der nicht vorhandenen Langzeit-Updates vor Augen halten - hier ist eigentlich fast immer nach ca. 3 Jahre Schluss.

Und ich gebe dir Recht hinsichtlich der Rootkits unter Linux: nach einer Infektion durch "t0rn" war der erste Hinweis auf die Infektion, dass das einloggen als root nicht mehr funktionierte.
Die Logs waren teils gelöscht und es hätte schon einen IT-Forensiker gebraucht, um hier vielleicht noch Informationen über den Angriffsvektor herauszufinden.


@cosinus:
Nur so als Tipp - ein Admin sollte, finde ich, gewisse stilistische Standards haben und "Netiquette" sollten ihm nicht nur ein Begriff sein sondern auch von ihm gelebt werden, sprich: vulgäre Beleidigungen müssen tabu sein, schließlich hat er Vorbildfunktion. Nur so lassen sich konstruktive Diskussionen führen.

Dante12 hatte die von mir (in Voraussetzung der Kenntnis allgemein bekannter Berichte und Hinweise in den einschlägigen Foren nur angerissenen) Punkte bereits "mit Fleisch" angereichert, wozu also noch mehr redundante Informationen liefern, die man in 1 Minute ergoogeln oder auf Wikipedia nachlesen kann.

cosinus 27.03.2016 17:12

Zitat:

Zitat von milchkeks (Beitrag 1574121)
@cosinus:
Nur so als Tipp - ein Admin sollte, finde ich, gewisse stilistische Standards haben und "Netiquette" sollten ihm nicht nur ein Begriff sein sondern auch von ihm gelebt werden, sprich: vulgäre Beleidigungen müssen tabu sein, schließlich hat er Vorbildfunktion. Nur so lassen sich konstruktive Diskussionen führen.

Dante12 hatte die von mir (in Voraussetzung der Kenntnis allgemein bekannter Berichte und Hinweise in den einschlägigen Foren nur angerissenen) Punkte bereits "mit Fleisch" angereichert, wozu also noch mehr redundante Informationen liefern, die man in 1 Minute ergoogeln oder auf Wikipedia nachlesen kann.

Wenn vom TO einfach nur planlos ellenlange Logs hier reingeknallt werden bekommt man schon den Eindruck, dass der einen verschaukeln will. Und dasselbe mit dir, DU hast behauptet in den Logs des TO findet sich etwas, sülzt irgendwas rein, meinst da würde es ja Hinweise gaben aber nach mehreren Nachfragen, endlich mal die Stellen aus den Logs zu zitieren, kommt nur weiteres Gesülze - wie soll man denn da vernünftig noch weiter diskutieren?

Wenn du etwas thematisierst dann sei auch konkret anstatt dich darüber zu beschweren, dass man dir dann Gesülze vorwirft und das versuchst als vulgäre Beleidigungen darzustellen. :kaffee:

Dante12 27.03.2016 19:23

Zitat:

Und dasselbe mit dir, DU hast behauptet in den Logs des TO findet sich etwas, sülzt irgendwas rein, meinst da würde es ja Hinweise gaben aber nach mehreren Nachfragen, endlich mal die Stellen aus den Logs zu zitieren, kommt nur weiteres Gesülze -
Danke da brauche ich nicht mehr kommentieren. :daumenhoc

dennissteins 01.04.2016 17:55

Einige Sachverhalte möchte ich im Folgenden nochmal klarstellen, da sich einige wundern, warum es hier nicht weiter geht.

a)Ich habe diesen seperaten Linux-Thread zum Titel gar nicht erstellt und wurde auch gar nicht gefragt, ob das für mich okay ist.

b) Der Titel des Threads fasst meine Infektionshypothese zusammen, und zwar im Rahmen des Kenntnisstsndes zum damaligen Zeitpunkt. Dieser hat sich bis heute weiterentwickelt, sodass ich von der o.g. Infektion nicht mehr ausgehen würde.

c) Meine Intention mit den Logs war es, möglichst viele Informationen zur Verfügung zu stellen, damit eine ich zügig nach fachlich Analyse eines Experten handeln kann.
Das ging nach hinten los und war mein Fehler.

d) Wie bereits von mir erwähnt setze ich mich erst seid 6 Monaten intensiver mit Linux auseinander, das sollte jedem Linux-Vertrauten deitlich signalisieten: hier kann ich wahrscheinlich keine dezidierte Rootkitanalye und Ubuntu oder andere erwarten.

Der Originalthread (Windows Schwerpunkt) steht im Diskussionsforum.

Ich dachte, die engagierten User hier sollten dafüber informiert werden, zumal hier bisher, trotz weniger Beteilugung deutlich ersthafter und und fachlich auf höhetem Niveau geantwortet als im Win-Abschnitt.

Fragerin 01.04.2016 20:59

Das Problem ist, dass du ganz viele Screenshots gepostet hast, von denen viele ganz normal aussehen, so dass es den Anschein eines "wahllosen" Postens hat, und dass du dich weigerst, zu erklären, wo denn nun auf diesen Screenshots dein Verdacht begründet ist. Also etwas konkretes dazu zu sagen und zu erklären. Ein oder zwei mit eindeutigen, präzise formulierten Fragen dazu hätten viel mehr gebracht und tun es vielleicht auch jetzt noch.

cosinus 03.04.2016 13:56

Hat er doch....loop devices sind seine "Beweise" :rofl:

dennisstein 16.04.2016 02:22

Bevor meine Installation mir Ubuntu wieder ganz umsonst war, hier noch einige Logs, bevor ich wahrscheinlich wieder nach dem Runterfahen formatieren kann.

RKhunter Teil 1

Code:

[05:46:01] Running Rootkit Hunter version 1.4.2 on bbs-sophos
[05:46:01]
[05:46:01] Info: Start date is Sa 16. Apr 05:46:01 CEST 2016
[05:46:01]
[05:46:01] Checking configuration file and command-line options...
[05:46:01] Info: Detected operating system is 'Linux'
[05:46:01] Info: Found O/S name: Ubuntu 15.10
[05:46:01] Info: Command line is /usr/bin/rkhunter -c
[05:46:01] Info: Environment shell is /bin/bash; rkhunter is using dash
[05:46:01] Info: Using configuration file '/etc/rkhunter.conf'
[05:46:01] Info: Installation directory is '/usr'
[05:46:01] Info: Using language 'en'
[05:46:01] Info: Using '/var/lib/rkhunter/db' as the database directory
[05:46:01] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[05:46:01] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[05:46:01] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[05:46:01] Info: No mail-on-warning address configured
[05:46:01] Info: X will be automatically detected
[05:46:01] Info: Using second color set
[05:46:01] Info: Found the 'basename' command: /usr/bin/basename
[05:46:01] Info: Found the 'diff' command: /usr/bin/diff
[05:46:01] Info: Found the 'dirname' command: /usr/bin/dirname
[05:46:01] Info: Found the 'file' command: /usr/bin/file
[05:46:01] Info: Found the 'find' command: /usr/bin/find
[05:46:01] Info: Found the 'ifconfig' command: /sbin/ifconfig
[05:46:01] Info: Found the 'ip' command: /sbin/ip
[05:46:01] Info: Found the 'ipcs' command: /usr/bin/ipcs
[05:46:01] Info: Found the 'ldd' command: /usr/bin/ldd
[05:46:01] Info: Found the 'lsattr' command: /usr/bin/lsattr
[05:46:01] Info: Found the 'lsmod' command: /sbin/lsmod
[05:46:01] Info: Found the 'lsof' command: /usr/bin/lsof
[05:46:01] Info: Found the 'mktemp' command: /bin/mktemp
[05:46:01] Info: Found the 'netstat' command: /bin/netstat
[05:46:01] Info: Found the 'perl' command: /usr/bin/perl
[05:46:01] Info: Found the 'pgrep' command: /usr/bin/pgrep
[05:46:01] Info: Found the 'ps' command: /bin/ps
[05:46:01] Info: Found the 'pwd' command: /bin/pwd
[05:46:01] Info: Found the 'readlink' command: /bin/readlink
[05:46:01] Info: Found the 'stat' command: /usr/bin/stat
[05:46:01] Info: Found the 'strings' command: /usr/bin/strings
[05:46:01] Info: System is not using prelinking
[05:46:01] Info: Using the '/usr/bin/sha256sum' command for the file hash checks
[05:46:01] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[05:46:01] Info: Stored hash values did not use a package manager
[05:46:01] Info: The hash function field index is set to 1
[05:46:01] Info: No package manager specified: using hash function '/usr/bin/sha256sum'
[05:46:01] Info: Previous file attributes were stored
[05:46:01] Info: Enabled tests are: all
[05:46:01] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[05:46:01] Info: Found ksym file '/proc/kallsyms'
[05:46:01] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[05:46:01] Info: Using 'date' to process epoch second times
[05:46:01]
[05:46:01] Checking if the O/S has changed since last time...
[05:46:01] Info: Nothing seems to have changed.
[05:46:01] Info: Locking is not being used
[05:46:01]
[05:46:01] Starting system checks...
[05:46:01]
[05:46:01] Info: Starting test name 'system_commands'
[05:46:01] Checking system commands...
[05:46:01]
[05:46:01] Info: Starting test name 'strings'
[05:46:01] Performing 'strings' command checks
[05:46:02]  Scanning for string /usr/sbin/ntpsx            [ OK ]
[05:46:02]  Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[05:46:02]  Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[05:46:02]  Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[05:46:02]  Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[05:46:02]  Scanning for string /usr/include/.../proc.h    [ OK ]
[05:46:02]  Scanning for string /usr/include/.../.bash_history [ OK ]
[05:46:02]  Scanning for string /usr/include/.../bkit-get  [ OK ]
[05:46:02]  Scanning for string /usr/include/.../bkit-dl    [ OK ]
[05:46:02]  Scanning for string /usr/include/.../bkit-screen [ OK ]
[05:46:02]  Scanning for string /usr/include/.../bkit-sleep [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-adore.o  [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../ls            [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../netstat        [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../lsof          [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../psr            [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../find          [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../pstree        [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../slocate        [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../du            [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../top            [ OK ]
[05:46:02]  Scanning for string /usr/sbin/...              [ OK ]
[05:46:02]  Scanning for string /usr/include/...            [ OK ]
[05:46:02]  Scanning for string /usr/include/.../.tmp      [ OK ]
[05:46:02]  Scanning for string /usr/lib/...                [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../.ssh          [ OK ]
[05:46:02]  Scanning for string /usr/lib/.../bkit-ssh      [ OK ]
[05:46:02]  Scanning for string /usr/lib/.bkit-            [ OK ]
[05:46:02]  Scanning for string /tmp/.bkp                  [ OK ]
[05:46:02]  Scanning for string /tmp/.cinik                [ OK ]
[05:46:02]  Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[05:46:02]  Scanning for string /lib/.sso                  [ OK ]
[05:46:02]  Scanning for string /lib/.so                    [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/clean      [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/dxr        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/read      [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/write      [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/lf        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/xl        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/xdr        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/psg        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/secure    [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/rdx        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/va        [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/cl.sh      [ OK ]
[05:46:02]  Scanning for string /var/run/...dica/last.log  [ OK ]
[05:46:02]  Scanning for string /usr/bin/.etc              [ OK ]
[05:46:02]  Scanning for string /etc/sshd_config            [ OK ]
[05:46:02]  Scanning for string /etc/ssh_host_key          [ OK ]
[05:46:02]  Scanning for string /etc/ssh_random_seed        [ OK ]
[05:46:02]  Scanning for string /dev/ptyp                  [ OK ]
[05:46:02]  Scanning for string /dev/ptyq                  [ OK ]
[05:46:02]  Scanning for string /dev/ptyr                  [ OK ]
[05:46:02]  Scanning for string /dev/ptys                  [ OK ]
[05:46:02]  Scanning for string /dev/ptyt                  [ OK ]
[05:46:02]  Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[05:46:02]  Scanning for string /dev/fd/.88/fresht          [ OK ]
[05:46:02]  Scanning for string /dev/fd/.88/zxsniff        [ OK ]
[05:46:02]  Scanning for string /dev/fd/.88/zxsniff.log    [ OK ]
[05:46:02]  Scanning for string /dev/fd/.99/.ttyf00        [ OK ]
[05:46:02]  Scanning for string /dev/fd/.99/.ttyp00        [ OK ]
[05:46:02]  Scanning for string /dev/fd/.99/.ttyq00        [ OK ]
[05:46:02]  Scanning for string /dev/fd/.99/.ttys00        [ OK ]
[05:46:03]  Scanning for string /dev/fd/.99/.pwsx00        [ OK ]
[05:46:03]  Scanning for string /etc/.acid                  [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/sched_host.2  [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/random_d.2    [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/TOHIDE        [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/cons.saver    [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[05:46:03]  Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[05:46:03]  Scanning for string /bin/sysback                [ OK ]
[05:46:03]  Scanning for string /usr/local/bin/sysback      [ OK ]
[05:46:03]  Scanning for string /usr/lib/.tbd              [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/t0rns    [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/t0rnp    [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/ssh.tgz  [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/top      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/login    [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/1i0n.sh  [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/mjy      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/tfn      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[05:46:03]  Scanning for string /usr/info/.torn/sh*        [ OK ]
[05:46:03]  Scanning for string /usr/src/.puta/.1addr      [ OK ]
[05:46:03]  Scanning for string /usr/src/.puta/.1file      [ OK ]
[05:46:03]  Scanning for string /usr/src/.puta/.1proc      [ OK ]
[05:46:03]  Scanning for string /usr/src/.puta/.1logz      [ OK ]
[05:46:03]  Scanning for string /usr/info/.t0rn            [ OK ]
[05:46:03]  Scanning for string /dev/.lib                  [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib              [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib          [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/lib/dev      [ OK ]
[05:46:03]  Scanning for string /dev/.lib/lib/scan          [ OK ]
[05:46:03]  Scanning for string /usr/src/.puta              [ OK ]
[05:46:03]  Scanning for string /usr/man/man1/man1          [ OK ]
[05:46:03]  Scanning for string /usr/man/man1/man1/lib      [ OK ]
[05:46:03]  Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[05:46:03]  Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[05:46:03]
[05:46:03] Info: Starting test name 'shared_libs'
[05:46:03] Performing 'shared libraries' checks
[05:46:03]  Checking for preloading variables              [ None found ]
[05:46:03]  Checking for preloaded libraries                [ None found ]
[05:46:03]
[05:46:03] Info: Starting test name 'shared_libs_path'
[05:46:03]  Checking LD_LIBRARY_PATH variable              [ Not found ]
[05:46:03]
[05:46:03] Info: Starting test name 'properties'
[05:46:03] Performing file properties checks
[05:46:03]  Checking for prerequisites                      [ OK ]
[05:46:05]  /usr/sbin/adduser                              [ Warning ]
[05:46:05] Warning: The file properties have changed:
[05:46:05]          File: /usr/sbin/adduser
[05:46:06]          Current hash: b26732ab356b3fa5e2e4a053e9a92cdaeb8c48197810701d38f3fbb4811741aa
[05:46:06]          Stored hash : 966f3c9cd1f833d35f85a790ad3efb9c312102c5
[05:46:06] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[05:46:06]  /usr/sbin/chroot                                [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/chroot
[05:46:06]          Current hash: abfbf805ef5d26118b56f9058648d4741b65a440ad2c0efbdd2c4e126f9eceb3
[05:46:06]          Stored hash : b590f922e1b90d941f6e17c1e8628f88c1e7d1bd
[05:46:06]  /usr/sbin/cron                                  [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/cron
[05:46:06]          Current hash: 0ac0dec694553e356cdf565ea9a2f8dda3b23e7cdd8d54bce5b6f2165db5724f
[05:46:06]          Stored hash : e0e91267e6a79646ed8cafd102a9e98fad435d5d
[05:46:06]  /usr/sbin/groupadd                              [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/groupadd
[05:46:06]          Current hash: e2ee45e23194cdb414593cb2660db0b095dff8d00f0d15d7844964c39e5f7b5a
[05:46:06]          Stored hash : 90765d5b2f9f3418f8020e0c363a8f116d5c3ad1
[05:46:06]  /usr/sbin/groupdel                              [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/groupdel
[05:46:06]          Current hash: 1bc6869cf0b2202491a5cff66a4b601b75d559f623d3088753bc94fcb5d60cfd
[05:46:06]          Stored hash : 39b301863c076a3bab345d63b3a6ebbba45573ec
[05:46:06]  /usr/sbin/groupmod                              [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/groupmod
[05:46:06]          Current hash: 6fe6eb53b180de1893a0897661e3293a67bfeff37b3d5c6d339f027263c50a15
[05:46:06]          Stored hash : b644c5d54d66eba10947481267a3d0058a3ec304
[05:46:06]  /usr/sbin/grpck                                [ Warning ]
[05:46:06] Warning: The file properties have changed:
[05:46:06]          File: /usr/sbin/grpck
[05:46:06]          Current hash: 0f343ae25c43e9228fbafdc2d9dee1d060dab41a55b17a5a2889bdf14a5c59e8
[05:46:06]          Stored hash : dbf2960bb15d27431d1fcdb326171b516ddeb50f
[05:46:07]  /usr/sbin/nologin                              [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/nologin
[05:46:07]          Current hash: 271a3219f26d7a71acaf17fca7ddc46a6b7ee1030e81ab86d9af63c46f209441
[05:46:07]          Stored hash : 522d03d335ba14e6b2edf8340c79757f84d43722
[05:46:07]  /usr/sbin/pwck                                  [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/pwck
[05:46:07]          Current hash: f3c3150240844035dcb780b11cf269e11bfb2cecdd8e1edf6d11b471b38b8390
[05:46:07]          Stored hash : 618886ceff8fc66a0c2edb1ca1638b6b268beedd
[05:46:07]  /usr/sbin/rsyslogd                              [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/rsyslogd
[05:46:07]          Current hash: 4fe70817c471d5f63c4cacc3ae28545eeb8c4101c03c5d78e53bed549a5eda95
[05:46:07]          Stored hash : e73ef3c5ff970d52b435a7f35f18a25008501143
[05:46:07]  /usr/sbin/tcpd                                  [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/tcpd
[05:46:07]          Current hash: e2f6d28d83953dcec5d713ba2015b23531864df372a1aa57c4ca8790b0d07b6c
[05:46:07]          Stored hash : cd9cfc19df7f0e4b7f9adfa4fe8c5d74caa53d86
[05:46:07]  /usr/sbin/useradd                              [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/useradd
[05:46:07]          Current hash: b636841e0997c2b6f3733b75b9a457e554def076ff30af989ac9f121be876557
[05:46:07]          Stored hash : 23961f70e84104790f9b6963425ab74ea6b97ec3
[05:46:07]  /usr/sbin/userdel                              [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/userdel
[05:46:07]          Current hash: 3487ce49e0e8e37778a6a7937d2b392ca3f12f0a51f233d0e05bf8e2e7d12665
[05:46:07]          Stored hash : 3abe2675ce163f322c7dd4dc5a82a9c22d846ef1
[05:46:07]  /usr/sbin/usermod                              [ Warning ]
[05:46:07] Warning: The file properties have changed:
[05:46:07]          File: /usr/sbin/usermod
[05:46:07]          Current hash: 362a72fb83de4bb621ecf8caebbd0a44c80de12824230a785e88a36c0a5a2b96
[05:46:07]          Stored hash : d3ad3f3f0257b18fc7eb2511f65cd9546caf2196
[05:46:08]  /usr/sbin/vipw                                  [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/sbin/vipw
[05:46:08]          Current hash: e43edf7a25c5e198590bb05ceb104e1a3bebf93105a71ea4aa72785377f6905d
[05:46:08]          Stored hash : 3e2318b9a6f147d9eb73b8022aea0df4dfd61729
[05:46:08]  /usr/sbin/unhide-linux                          [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/sbin/unhide-linux
[05:46:08]          Current hash: a41da60d4325d0805899b019f13ece793a2d9554cd667380bab8bb93a41b8332
[05:46:08]          Stored hash : b0a4f70f4284f3a0839f1ed33d15ec01b7ec8083
[05:46:08]  /usr/sbin/unhide-posix                          [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/sbin/unhide-posix
[05:46:08]          Current hash: 589b2bfe9200677cf4a213488217ce06c70acfc62d666eaaf2fcc68a832714d2
[05:46:08]          Stored hash : 14defd2522a5becafff2d7a6b4192d194c3b096e
[05:46:08]  /usr/sbin/unhide-tcp                            [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/sbin/unhide-tcp
[05:46:08]          Current hash: 92a492bda0c9277e0481ad1f3efc71eceb9a4ee3b04b897564c79402c8a143ce
[05:46:08]          Stored hash : 67d8f617e9e067c235e53d591f6ce64a7b65ab00
[05:46:08]  /usr/bin/awk                                    [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/bin/awk
[05:46:08]          Current hash: 91c3e9551264fc2b8a46a104715d51c13d717460f460e5d0d97295c69196ed1c
[05:46:08]          Stored hash : 3462fce89f3e37f0419cf118d90d6c36887e1609
[05:46:08]  /usr/bin/basename                              [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/bin/basename
[05:46:08]          Current hash: 0d173084775292059489a60ebd9978fd5202e58ff8d4c08a4a77e4148c9fc339
[05:46:08]          Stored hash : ce119e2c0d99b8d0fede01cbd565f16472b6f6c4
[05:46:08]  /usr/bin/chattr                                [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/bin/chattr
[05:46:08]          Current hash: 8bed510f9778a9b9350ea811230f56f2389ffa1bbda595b1f1d31c328d174b8a
[05:46:08]          Stored hash : 2d34b4c7aa564c82c8e6f98c1ffb6db783a841b2
[05:46:08]  /usr/bin/curl                                  [ Warning ]
[05:46:08] Warning: The file properties have changed:
[05:46:08]          File: /usr/bin/curl
[05:46:08]          Current hash: be7fc9358c59203365c697aa690c199e3b82a4f434f0fc17645adef2943a3999
[05:46:08]          Stored hash : ebdfdee34ae05e35ce7e14f2850b53aa3d5f11cf
[05:46:08]  /usr/bin/cut                                    [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/cut
[05:46:09]          Current hash: c3dabc16adbc435346c16c27a93da2f594e8a2b1a997d635316dbe6c722453e6
[05:46:09]          Stored hash : 7b896a784f3251a73ae95ea3edc7517252b956a5
[05:46:09]  /usr/bin/diff                                  [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/diff
[05:46:09]          Current hash: cd61d2739c43aba7bacc478e1ab790d53bab55802ca662e6b1aac98e90f0bd4e
[05:46:09]          Stored hash : 907ea004a7830cc53fe53db52c26b16fdf17d5ee
[05:46:09]  /usr/bin/dirname                                [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/dirname
[05:46:09]          Current hash: b3b8d2b9675c0fc522387e7cd7b871bf1fb006b26536a097a66fb828ee42ad4c
[05:46:09]          Stored hash : d9f380f1216303d7db1af6538db4561a90537e53
[05:46:09]  /usr/bin/dpkg                                  [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/dpkg
[05:46:09]          Current hash: 75869329a6e4836540f6668faa742b7924d0dbabe124251184e538e3b360fffa
[05:46:09]          Stored hash : cd56737010133a0c5b85b060d33b1cd21d63050a
[05:46:09]  /usr/bin/dpkg-query                            [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/dpkg-query
[05:46:09]          Current hash: 4b52d7f69c86b7ef392e6207edfa44f11fed9b3487114ecaa7dedb8255cf31cd
[05:46:09]          Stored hash : a7aaa69d65a03133c55eceb5d388ada61ec30272
[05:46:09]  /usr/bin/du                                    [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/du
[05:46:09]          Current hash: 9a77c3b4e2859c9a1d3e31cda513964ce1602132fb994a8ba59e82e64a138f43
[05:46:09]          Stored hash : fc798299cdaf4243b70f7cced589f808457328a2
[05:46:09]  /usr/bin/env                                    [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/env
[05:46:09]          Current hash: 6e7eb2d4f3c12afc67e9cd64db7c38b9994626893e1a5cb394bbf32d02852ba2
[05:46:09]          Stored hash : 14996bf223a4f47c02505c2eb82996b31127e322
[05:46:09]  /usr/bin/file                                  [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/file
[05:46:09]          Current hash: 2749099cfeb3834bd6a255dd9cc26d0e6796254a8fa93be1cb922af463a8d50d
[05:46:09]          Stored hash : a796fca1bea54b05cea8a88be0f51a9f9e1f6f40
[05:46:09]  /usr/bin/find                                  [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/find
[05:46:09]          Current hash: f547b976f28c2edcb5fbe1f1c2969ed5123cf7af1ff2802b7355b2acd6959d33
[05:46:09]          Stored hash : 0976ef2017360581ede6489c04723dc9d8e630d7
[05:46:09]  /usr/bin/GET                                    [ Warning ]
[05:46:09] Warning: The file properties have changed:
[05:46:09]          File: /usr/bin/GET
[05:46:09]          Current hash: b38bbacb975fd69981a8bd41d866c9af75ededd2c5a4d6118b4b41aeb328ac72
[05:46:09]          Stored hash : e6e5247e0710669383e14160d54396fca4a1ede2
[05:46:10]  /usr/bin/groups                                [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/groups
[05:46:10]          Current hash: 199a3b5d0772072dc1abb92c279b49e255e7fa4cc51eb59ecaa44550d52acc15
[05:46:10]          Stored hash : ac12db00ed48f79ee94535a483c0a199ab517e02
[05:46:10]  /usr/bin/head                                  [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/head
[05:46:10]          Current hash: fc22d2def2c4603c202e0ac66f979dc2ad3c9fea075e6941ab78f74a8cfebe02
[05:46:10]          Stored hash : 26cad14006da2c88c8c0c9b67c6bd9beec0517a8
[05:46:10]  /usr/bin/id                                    [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/id
[05:46:10]          Current hash: f425012c7175a97fb6829634ead4d58a9449f25ac3f8307dac9a6c4ccd0873cb
[05:46:10]          Stored hash : e1177f196b86a87da25bd6b3dace2e7874ef055a
[05:46:10]  /usr/bin/killall                                [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/killall
[05:46:10]          Current hash: 2641776193b7a6d0ee4931bfdca253b3f1ebad0c74c2eec871fc6e453439cbc3
[05:46:10]          Stored hash : 1034dea61785a938d0f468006319ebf140640201
[05:46:10]  /usr/bin/last                                  [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/last
[05:46:10]          Current hash: 988a6fe34da3d00dd7aa89112d6b38cfaa5ec4ca9e3dd525138b69927f7d20e3
[05:46:10]          Stored hash : 52d5bf4d24fb66a71cea6758419d27f59ff2b491
[05:46:10]  /usr/bin/lastlog                                [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/lastlog
[05:46:10]          Current hash: 43fff3bb733fbfae76c26724d54c8ae11c1ae921d90bc57b75e12d858175d3f2
[05:46:10]          Stored hash : 6d3371aa78bf864657dfd4df06177476db1162e8
[05:46:10]  /usr/bin/ldd                                    [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/ldd
[05:46:10]          Current hash: 7b253d20dcc8c0d57e1e15bdae100f57e1a3a80e6e5c7b5940f695a2dba5c622
[05:46:10]          Stored hash : 5d8d12cb912aae4d6bbce8d38d0ea73ddd76c7de
[05:46:10] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[05:46:10]  /usr/bin/less                                  [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/less
[05:46:10]          Current hash: 9d5de353eac7bbb6266e84b0ad7766216a6e65e6538a36360a0ea00d2287e054
[05:46:10]          Stored hash : 77ba0b7718b53ac019808400592d7c7f1a736e5d
[05:46:10]  /usr/bin/locate                                [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/locate
[05:46:10]          Current hash: af93ee08472682d0b305071af17ddceca819b067f4b748cb3280d0a0cc8c8f23
[05:46:10]          Stored hash : 1e1017d8cc4ec3fec5de286391d288889679da98
[05:46:10]  /usr/bin/logger                                [ Warning ]
[05:46:10] Warning: The file properties have changed:
[05:46:10]          File: /usr/bin/logger
[05:46:10]          Current hash: fd0dc190a2f44b4d1e5024aa9313879832524a0279031eead78224747886788c
[05:46:10]          Stored hash : cfdc862738d9740dc424e6efc9ee9a4f9d19383a
[05:46:11]  /usr/bin/lsattr                                [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/lsattr
[05:46:11]          Current hash: 12562937b0c0ce92cc9e50348a4a184939e8516e3af8d958508aad1346d0d2be
[05:46:11]          Stored hash : 54faffe2cf9e65b88babb971b9e17b46d4af8bf4
[05:46:11]  /usr/bin/lsof                                  [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/lsof
[05:46:11]          Current hash: dd8553477e01410b5f8e955603510ee70c48b679bef6a611b135049bb1cd2080
[05:46:11]          Stored hash : a09e74f493b075c6febaa4fbeb0a59445f404937
[05:46:11]  /usr/bin/mail                                  [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/mail
[05:46:11]          Current hash: 760699dbec6e9ab1f6fdda9a9373a7bc5b8708fe60ce39fba58f952e3d099444
[05:46:11]          Stored hash : ae529220b04d2551a08d0ab4b7d13d1c6a4a2830
[05:46:11]  /usr/bin/md5sum                                [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/md5sum
[05:46:11]          Current hash: d2feabf9a41ac50c7bfc7d3060997a4f927f0b0c339daa8fbe8a55d2f943b979
[05:46:11]          Stored hash : 3a37187f60dc9259e7e1f648b5291ca7b1e389e0
[05:46:11]  /usr/bin/mlocate                                [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/mlocate
[05:46:11]          Current hash: af93ee08472682d0b305071af17ddceca819b067f4b748cb3280d0a0cc8c8f23
[05:46:11]          Stored hash : 1e1017d8cc4ec3fec5de286391d288889679da98
[05:46:11]  /usr/bin/newgrp                                [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/newgrp
[05:46:11]          Current hash: 7f34d2c65c974696b4f9bf74460fd4ae24063d6bcec6533b62c89cf5bfa082f6
[05:46:11]          Stored hash : f53350f9a469b43997bc7ee663045bdaf646d62c
[05:46:11]  /usr/bin/passwd                                [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/passwd
[05:46:11]          Current hash: ed0d7e84c0f1e56c092c4939de549ec67968a252257d9d90c369a8bb207809b3
[05:46:11]          Stored hash : 6b1f0bea85a7585914d78621ff205854d01acc08
[05:46:11]  /usr/bin/perl                                  [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/perl
[05:46:11]          Current hash: c980066b572f250b51f59ccdd75b8321a8e164523e9edfa6ea876d45d832e91c
[05:46:11]          Stored hash : db619fc87b82c399c83cb672a19588774f0b0f9b
[05:46:11]  /usr/bin/pgrep                                  [ Warning ]
[05:46:11] Warning: The file properties have changed:
[05:46:11]          File: /usr/bin/pgrep
[05:46:11]          Current hash: fc7d8bb813af089fbe9d2badcb6caff1f600c8b62ee33ff64ac7f4529bf4a855
[05:46:12]          Stored hash : 0fd5048e0acf92556960ac173fa4471c9e573b4c
[05:46:12]  /usr/bin/pkill                                  [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/pkill
[05:46:12]          Current hash: fc7d8bb813af089fbe9d2badcb6caff1f600c8b62ee33ff64ac7f4529bf4a855
[05:46:12]          Stored hash : 0fd5048e0acf92556960ac173fa4471c9e573b4c
[05:46:12]  /usr/bin/pstree                                [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/pstree
[05:46:12]          Current hash: f5f9af545b0cd9a104187b728e94509ca42ca7d19f6c1e92107f58ac89907b74
[05:46:12]          Stored hash : 4e21b8ea426b1e10f7df78e9bf445a84cee36c66
[05:46:12]  /usr/bin/rkhunter                              [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/rkhunter
[05:46:12]          Current hash: 522f8c9953f068b9f4d9b861ff3c162751ffc3324963b17617d0bbbc22227bba
[05:46:12]          Stored hash : be0db8f6e638164cc6abcaebc34f90cb9a832182
[05:46:12]  /usr/bin/runcon                                [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/runcon
[05:46:12]          Current hash: 6ef25abf93a863881ba78c476f3e5859b84459447e41d7b2c9f52a635fcc749c
[05:46:12]          Stored hash : f52469f966b0f662a0b2d0b24b6c692a299ef600
[05:46:12]  /usr/bin/sha1sum                                [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/sha1sum
[05:46:12]          Current hash: e510792a4ececb78e32e2d07f1cebc8a8649438d86dd5400704f3b5937a627c1
[05:46:12]          Stored hash : e36cc1b35ba13f163c8481ec9b196a0e51a725d0
[05:46:12]  /usr/bin/sha224sum                              [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/sha224sum
[05:46:12]          Current hash: 69fa215cb61af5d45f773fbb939635f33a859d44e41dad6f9c08761b401e9e78
[05:46:12]          Stored hash : bc2abe93e0e7749c9d1261c4ce5d0649187fea7e
[05:46:12]  /usr/bin/sha256sum                              [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/sha256sum
[05:46:12]          Current hash: f855e9d7453561022df38f695ad7daba93c8fd1a3c6dae534ad665265232120f
[05:46:12]          Stored hash : 48cc1aee4a00d85ccaa885cec994ef4bece90593
[05:46:12]  /usr/bin/sha384sum                              [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/sha384sum
[05:46:12]          Current hash: fa6df178ac6cc70cabd2ec9ab2de4efe5cb6e2eced25413d0c6cba347e892c63
[05:46:12]          Stored hash : cb6d6e6fc9d236fc12946add2620d7aafe42d373
[05:46:12]  /usr/bin/sha512sum                              [ Warning ]
[05:46:12] Warning: The file properties have changed:
[05:46:12]          File: /usr/bin/sha512sum
[05:46:12]          Current hash: 69ee6b50010f6a5a09cc2a2daa3836ed31d4e4f7a277490e759f81e81401464f
[05:46:12]          Stored hash : 4240d540620baa729899a3b942d18891199025e8
[05:46:13]  /usr/bin/size                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/size
[05:46:13]          Current hash: fd068f1b22fd74204858cff7f3b3e3a493a1971c0c70802582ae39362f7ff705
[05:46:13]          Stored hash : 06111baaed602204a5ee1c5051e98bc9076860f5
[05:46:13]  /usr/bin/sort                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/sort
[05:46:13]          Current hash: b2ab7b5c56c363bbadef4f0a75345917ea53fe9015cc64908d18773eaabf0c93
[05:46:13]          Stored hash : a6a9fbf310ec415544bef74993d16896186dee9e
[05:46:13]  /usr/bin/ssh                                    [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/ssh
[05:46:13]          Current hash: 2b5d0118c7b5401b8466683564662e0799752952b8f537b18fae638a491c45af
[05:46:13]          Stored hash : 8a13fbb97c609d2dff08150a8e11870e3da3c984
[05:46:13]  /usr/bin/stat                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/stat
[05:46:13]          Current hash: 7dd1ba73896e9e6f76bce7fea951086f3f6aefd416d21f891070611ef84f8871
[05:46:13]          Stored hash : 1a3e07652ca5227bbe9b7c88f529bcedf21c2843
[05:46:13]  /usr/bin/strace                                [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/strace
[05:46:13]          Current hash: 2d20afd0ae46abb8ef442bd39bf602b1ad6dd8bc8be4bd6cb9fc69ba9afd8f55
[05:46:13]          Stored hash : 01bb37ec082045f3d4d39c5f48df607e09f9882e
[05:46:13]  /usr/bin/strings                                [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/strings
[05:46:13]          Current hash: d021a5d313adc2edbb7e5baaa8b75a6db8b888ede9a784679642b0e060719e02
[05:46:13]          Stored hash : 9641523123f6abbef34a36bd995457f319482404
[05:46:13]  /usr/bin/sudo                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/sudo
[05:46:13]          Current hash: 2ad491f3dbdac3ff40b46565d253e5e84e653af7c05d5cca2fa8848f46e49ee8
[05:46:13]          Stored hash : a0dac5cc4b520e4cd45e9cfed381ac66960f40a2
[05:46:13]  /usr/bin/tail                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/tail
[05:46:13]          Current hash: 82bd160a5ce7246f0951793940319e690a95ec2aa59a9a42f8b91e5150358696
[05:46:13]          Stored hash : 7e4988299aee8129cd129f06fef6688cbf8fe0f7
[05:46:13]  /usr/bin/telnet                                [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/telnet
[05:46:13]          Current hash: d3379c3587823675a2324fefe702c25f52776bc47cab73d7c128e82426887583
[05:46:13]          Stored hash : 6bda2713e3bb0d48c4919606e0c24e132175d855
[05:46:13]  /usr/bin/test                                  [ Warning ]
[05:46:13] Warning: The file properties have changed:
[05:46:13]          File: /usr/bin/test
[05:46:13]          Current hash: e6e8a3610ff040c8e75eb2dd3e4aace7e2181caf13a36a9fddc66df6d9aed407
[05:46:13]          Stored hash : 367e4e59dfe36b96dcf34bae9a2c5d2e5b0acd40
[05:46:14]  /usr/bin/top                                    [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/top
[05:46:14]          Current hash: 3b9a065ac4a781ca70052c8b09cb11a4b519cd4a486872209156f2fa89c3c672
[05:46:14]          Stored hash : 3dbd0cad6dcda87f1ee81597fbe9d4472ffaa28c
[05:46:14]  /usr/bin/touch                                  [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/touch
[05:46:14]          Current hash: 592bf9c6a1204f9a2adc782d410677c7eca3af1b8134caf85c54e1e9b75c39b9
[05:46:14]          Stored hash : 3d11398da75dcee8dc34204a5a4624e5ee45b5ea
[05:46:14]  /usr/bin/tr                                    [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/tr
[05:46:14]          Current hash: 5281bd37d76657804dabf24e534659e0f5801825981ddbc85e6a8e3464c090dc
[05:46:14]          Stored hash : a99a52338eb13d36873116a7734d83dda5f3ceea
[05:46:14]  /usr/bin/uniq                                  [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/uniq
[05:46:14]          Current hash: 962b6401f2e0ef8ee8da90c7b2927b9149f613d118413aff6f68bd81443654b3
[05:46:14]          Stored hash : 98e5d7cb9890667d210f4b37df6ff25c0fa2e177
[05:46:14]  /usr/bin/users                                  [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/users
[05:46:14]          Current hash: 0cf97082d0dcb5939212b73f991f6ab11790dcd4ed1d490865a4b92583af19ac
[05:46:14]          Stored hash : 7a4f62fae74b51fcb8290beae14f3778df2b8663
[05:46:14]  /usr/bin/vmstat                                [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/vmstat
[05:46:14]          Current hash: 955360adb7fa8a69f2d67371540da272d2f3a5e2d14e77fa8ea7d3412fe7ea78
[05:46:14]          Stored hash : a5fa50efebb7282c80e807c00c0776a4f5233c20
[05:46:14]  /usr/bin/w                                      [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/w
[05:46:14]          Current hash: 4acf846dd7c29c028a9453804b98483778390053011c132d7dec96e07d9149be
[05:46:14]          Stored hash : 84b1649d3c541fd2d81d361c24b7338588865c68
[05:46:14]  /usr/bin/watch                                  [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/watch
[05:46:14]          Current hash: b484860d2bd3ad2371974778a0662b806101b4102fd5ea69664d058571ff1cbb
[05:46:14]          Stored hash : 22e384388a0bf9ea1d01ff3970391318985bb8bb
[05:46:14]  /usr/bin/wc                                    [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/wc
[05:46:14]          Current hash: 23c06d7658ae3f4f11d9a71da847ee7e27c1d18efdcdf22719f133e7977f9e63
[05:46:14]          Stored hash : 7a1f65b4bc0f15bdf68409d8897552b7da393b2e
[05:46:14]  /usr/bin/wget                                  [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/wget
[05:46:14]          Current hash: 6c72ef6959f9be21b4693d4a0d3cf2f0706f24ca5e9a451ba5a291db9f1dd469
[05:46:14]          Stored hash : 24c983093f5ff807650b7582934012eed64812d8
[05:46:14]  /usr/bin/whatis                                [ Warning ]
[05:46:14] Warning: The file properties have changed:
[05:46:14]          File: /usr/bin/whatis
[05:46:14]          Current hash: 7c8ca90f64b33c15f9a8a7983952b59742b7f8d5063a3c41b7bb27cb7565c93d
[05:46:15]          Stored hash : 5f5903825c61b0c7b9e1cb0f291c3ddb8e327609
[05:46:15]  /usr/bin/whereis                                [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/whereis
[05:46:15]          Current hash: 7c0758c09b3148c54492977a342f8c532a438c59a7fd512eacf29b0767994968
[05:46:15]          Stored hash : cbf487a9a88566d15dc1bdab9be9eb315e636c2d
[05:46:15]  /usr/bin/which                                  [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/which
[05:46:15]          Current hash: 7bdde142dc5cb004ab82f55adba0c56fc78430a6f6b23afd33be491d4c7c238b
[05:46:15]          Stored hash : cd2cdf42c04fba4123f4b8f12bca9bbd76552c95
[05:46:15]  /usr/bin/who                                    [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/who
[05:46:15]          Current hash: f1dd6dc503c8a7a868285c41509f6f457f8143668b4f89629c4bb6f96369b3db
[05:46:15]          Stored hash : 2376e2db78736e8b4663840e26e947bef0c51286
[05:46:15]  /usr/bin/whoami                                [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/whoami
[05:46:15]          Current hash: 3277d2ecc82f7fa37e906929615ab464be685986388755ed709c8406ede8e250
[05:46:15]          Stored hash : ee9517192f8434384c3956f18a49b507bd00bbff
[05:46:15]  /usr/bin/unhide                                [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/unhide
[05:46:15]          Current hash: a41da60d4325d0805899b019f13ece793a2d9554cd667380bab8bb93a41b8332
[05:46:15]          Stored hash : b0a4f70f4284f3a0839f1ed33d15ec01b7ec8083
[05:46:15]  /usr/bin/mawk                                  [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/mawk
[05:46:15]          Current hash: 91c3e9551264fc2b8a46a104715d51c13d717460f460e5d0d97295c69196ed1c
[05:46:15]          Stored hash : 3462fce89f3e37f0419cf118d90d6c36887e1609
[05:46:15]  /usr/bin/lwp-request                            [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/lwp-request
[05:46:15]          Current hash: b38bbacb975fd69981a8bd41d866c9af75ededd2c5a4d6118b4b41aeb328ac72
[05:46:15]          Stored hash : e6e5247e0710669383e14160d54396fca4a1ede2
[05:46:15]  /usr/bin/bsd-mailx                              [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/bsd-mailx
[05:46:15]          Current hash: 760699dbec6e9ab1f6fdda9a9373a7bc5b8708fe60ce39fba58f952e3d099444
[05:46:15]          Stored hash : ae529220b04d2551a08d0ab4b7d13d1c6a4a2830
[05:46:15]  /usr/bin/telnet.netkit                          [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/telnet.netkit
[05:46:15]          Current hash: d3379c3587823675a2324fefe702c25f52776bc47cab73d7c128e82426887583
[05:46:15]          Stored hash : 6bda2713e3bb0d48c4919606e0c24e132175d855
[05:46:15]  /usr/bin/w.procps                              [ Warning ]
[05:46:15] Warning: The file properties have changed:
[05:46:15]          File: /usr/bin/w.procps
[05:46:15]          Current hash: 4acf846dd7c29c028a9453804b98483778390053011c132d7dec96e07d9149be
[05:46:15]          Stored hash : 84b1649d3c541fd2d81d361c24b7338588865c68
[05:46:16]  /sbin/depmod                                    [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/depmod
[05:46:16]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:16]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:16]  /sbin/fsck                                      [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/fsck
[05:46:16]          Current hash: f2fe40a64cd998f49ca36918410559243eab39cb417b661eeaf1864aa8f07e36
[05:46:16]          Stored hash : 8850b196d1ae72ecb933d16a73d6b2ed3c4907d0
[05:46:16]  /sbin/ifconfig                                  [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/ifconfig
[05:46:16]          Current hash: 44731bbb6523d8bbfdcc09e2eb6f8341524c0656ef8ab6c62ed758afac95140c
[05:46:16]          Stored hash : add07092b8f96e5c0d36be45d53692ace3a8d34b
[05:46:16]  /sbin/ifdown                                    [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/ifdown
[05:46:16]          Current hash: 651db729c5f8677f4c8827bb24c712892b2d7c8becc763e49d98b5232f1452e2
[05:46:16]          Stored hash : 284790aec5ad6cee524b309788f039348ee85a51
[05:46:16]  /sbin/ifup                                      [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/ifup
[05:46:16]          Current hash: 651db729c5f8677f4c8827bb24c712892b2d7c8becc763e49d98b5232f1452e2
[05:46:16]          Stored hash : 284790aec5ad6cee524b309788f039348ee85a51
[05:46:16]  /sbin/init                                      [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/init
[05:46:16]          Current hash: 97089b739ae4727d312eff88901d5c088f29f72f878c8213112e41559e46bcf9
[05:46:16]          Stored hash : f27f7f1a84e12120e587148aa6e97c5545c7f909
[05:46:16]  /sbin/insmod                                    [ Warning ]
[05:46:16] Warning: The file properties have changed:
[05:46:16]          File: /sbin/insmod
[05:46:16]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:17]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:17]  /sbin/ip                                        [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/ip
[05:46:17]          Current hash: d1a0a23a3a2686957237b350516569184af7d5a494b6b4443510fa1ae4784891
[05:46:17]          Stored hash : ce5da9e0fb5f58ce574c6bf5dcc6781a8a36e5d3
[05:46:17]  /sbin/lsmod                                    [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/lsmod
[05:46:17]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:17]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:17]  /sbin/modinfo                                  [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/modinfo
[05:46:17]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:17]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:17]  /sbin/modprobe                                  [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/modprobe
[05:46:17]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:17]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:17]  /sbin/rmmod                                    [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/rmmod
[05:46:17]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:17]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:17]  /sbin/route                                    [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/route
[05:46:17]          Current hash: bcec0906e2f49b98182a810fd751735efb02192dbfb8d5e3d3787cfa63843af5
[05:46:17]          Stored hash : 7fa0d95fec023b2db88162e7b4f554552e6510d1
[05:46:17]  /sbin/runlevel                                  [ Warning ]
[05:46:17] Warning: The file properties have changed:
[05:46:17]          File: /sbin/runlevel
[05:46:17]          Current hash: 0cb19a37bc96d70bcdabae8f7723a6c74c376e367f91531a82254878759b9e9c
[05:46:17]          Stored hash : ff23fef9209eb18843944a2a68bccaecaeadbaf1
[05:46:18]  /sbin/sulogin                                  [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /sbin/sulogin
[05:46:18]          Current hash: ab0e37346995372da64001067970dbcef03b871b459ba889ba09f60f68768119
[05:46:18]          Stored hash : 42581c8b311666b697f699559c1210513b826fb3
[05:46:18]  /sbin/sysctl                                    [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /sbin/sysctl
[05:46:18]          Current hash: fcbe69441937ec7453715cd8a35a356ca26f2ecf00df8a50d00570d17bb1cd5a
[05:46:18]          Stored hash : a0232e153465a4b70fa78b1ece2b39b7e976d61c
[05:46:18]  /bin/bash                                      [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /bin/bash
[05:46:18]          Current hash: 2b607f16148bcd2c95cc1069df4ca6c0ac60f1c049451f6d323c0b0b657f9206
[05:46:18]          Stored hash : a6cabb20a54bba91d925d8d97d079ffc6437c6d8
[05:46:18]  /bin/cat                                        [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /bin/cat
[05:46:18]          Current hash: 8d6da6a751b66c3cdfebb56cc89a72b9a64a42f4c4e7dc8e198698bba280008a
[05:46:18]          Stored hash : 53d12746d7abba6d23d807ed01bcea0c824d3a9c
[05:46:18]  /bin/chmod                                      [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /bin/chmod
[05:46:18]          Current hash: 28be01cf30115c49d511f92161455538c4fd44775e46a390ea8cce4eeb7ec63b
[05:46:18]          Stored hash : ed933bb26ded3ea2c815a45778f54d33284e97c7
[05:46:18]  /bin/chown                                      [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /bin/chown
[05:46:18]          Current hash: b2c06da3a417737602d9b486c6c3105ac52c8f9c0e019b58c7297bd7e266db91
[05:46:18]          Stored hash : 17074822f5a9c0ebc275b247f6ea6a1d0338c3ce
[05:46:18]  /bin/cp                                        [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:18]          File: /bin/cp
[05:46:18]          Current hash: 43ee5f18dd9cdaff7c5ab8842cd6341c0e29be905b8195f24c9b069cc49ac196
[05:46:18]          Stored hash : 6b94202b1885ec2c00dfb537d94e6ab15db00214
[05:46:18]  /bin/date                                      [ Warning ]
[05:46:18] Warning: The file properties have changed:
[05:46:19]          File: /bin/date
[05:46:19]          Current hash: 6127e7afa1338ff0f031a31c5b8282b3515fe35a94ec9ab83bf7026a410ddec2
[05:46:19]          Stored hash : 0806310d3e00e4e20d9bb09306501f270bc1fae5
[05:46:19]  /bin/df                                        [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/df
[05:46:19]          Current hash: a421040f5aa9236a92148b98edc6b62e5ccae197aa788f488990f68509132151
[05:46:19]          Stored hash : 50c5921d20a679e8762c08af1ecaabfb1a05b24b
[05:46:19]  /bin/dmesg                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/dmesg
[05:46:19]          Current hash: 338db6578e6129ecc9e9ca4bd4641cab88bc8ae528a3a238b7f4d422ea2a6a91
[05:46:19]          Stored hash : 8687790451d286e4f643872c67bf09fcf9a2e7ec
[05:46:19]  /bin/echo                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/echo
[05:46:19]          Current hash: 44c212c3828eb931b4b45d2ac672fd49dcd4b7ee50f52e8460f473c3c2758d87
[05:46:19]          Stored hash : a72d805016b81f76182968836c692cb1eced8087
[05:46:19]  /bin/ed                                        [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/ed
[05:46:19]          Current hash: c00c78fa172ac82d126ae0df152a2b72f252e7c5d19f14d592af0d39fea9f20b
[05:46:19]          Stored hash : 0d509cbe4531ea3ecf1455552fdc222335019390
[05:46:19]  /bin/egrep                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/egrep
[05:46:19]          Current hash: 3c4178db943e4e8e667e32d9ac5992110f17dffdc0dfd3863d6184d693be2376
[05:46:19]          Stored hash : 79c712245588e086b95ad5375fcf4a32d7312485
[05:46:19] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[05:46:19]  /bin/fgrep                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/fgrep
[05:46:19]          Current hash: f364bd304ababe3b2dd9149fbbf816fdf6e55c093ca3b1121859dd934e5dde2c
[05:46:19]          Stored hash : a52df03b928b802bf86780a4a411519c4bfc7c14
[05:46:19] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[05:46:19]  /bin/fuser                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/fuser
[05:46:19]          Current hash: 9c7eb7b89bbff88a1ba80b4f068c5eba00436407c8f4494aa851de9934ec0b29
[05:46:19]          Stored hash : ce27b62c83648b9022fde65c2a2f9b2ea38d347d
[05:46:19]  /bin/grep                                      [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/grep
[05:46:19]          Current hash: 5be890e64503dc898b9406378b95bb7d3487f1bfebb458ee49502e486e5fc921
[05:46:19]          Stored hash : 3995b06c261e13c69a2ebd8bb51fe45f01a02b32
[05:46:19]  /bin/ip                                        [ Warning ]
[05:46:19] Warning: The file properties have changed:
[05:46:19]          File: /bin/ip
[05:46:19]          Current hash: d1a0a23a3a2686957237b350516569184af7d5a494b6b4443510fa1ae4784891
[05:46:19]          Stored hash : ce5da9e0fb5f58ce574c6bf5dcc6781a8a36e5d3
[05:46:20]  /bin/kill                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/kill
[05:46:20]          Current hash: b566730c421725ab09f29ae8cdcda7aa83295fdb24d9bb246bae7f8ec7fdff5a
[05:46:20]          Stored hash : f06668807a4e6c103bdc70913b122c3a026e37dd
[05:46:20]  /bin/less                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/less
[05:46:20]          Current hash: 9d5de353eac7bbb6266e84b0ad7766216a6e65e6538a36360a0ea00d2287e054
[05:46:20]          Stored hash : 77ba0b7718b53ac019808400592d7c7f1a736e5d
[05:46:20]  /bin/login                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/login
[05:46:20]          Current hash: cf692e9dbea54d1228ce9ec890ecb6d3c86e540b0100c0dcdf33895cd37901d9
[05:46:20]          Stored hash : 71f5bd17224e3e8b53bbfac5e263b0624823a66c
[05:46:20]  /bin/ls                                        [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/ls
[05:46:20]          Current hash: 0b786b336b0391b56dabb7b078a23ec4295115628cfd4b635f4d8ae5ae0cfafc
[05:46:20]          Stored hash : 68837276277029c9ca14c262b01d28512226bff7
[05:46:20]  /bin/lsmod                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/lsmod
[05:46:20]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:20]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:20]  /bin/mktemp                                    [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/mktemp
[05:46:20]          Current hash: cab2a03368627e01d9f5c7aba32b42a0657321b306a8133a4de4cfd68eda7976
[05:46:20]          Stored hash : f4dca855e85a092e113d16227789e98516fbeb50
[05:46:20]  /bin/more                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/more
[05:46:20]          Current hash: f52b8e3f464873032cc2e393fa2fa5d4f678fe17eb89b1398adebb7f826f91ff
[05:46:20]          Stored hash : 228bcdd7f34eea6f8ed7b9c2bc2920664d15c42b
[05:46:20]  /bin/mount                                      [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/mount
[05:46:20]          Current hash: 37165d647b40243d219b947c060b3cecb91d8a8bb529afb7c8fdf5b00abffdef
[05:46:20]          Stored hash : 81d572586ffa44094a816c1a661a42aaf2be2507
[05:46:20]  /bin/mv                                        [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/mv
[05:46:20]          Current hash: 7457f616b3eab7910f7ed006e4f7145442a9d8e24126247556e8180222ff8d62
[05:46:20]          Stored hash : d97fa1490fc424d5b0d6afdcb63096d013bd4465
[05:46:20]  /bin/netstat                                    [ Warning ]
[05:46:20] Warning: The file properties have changed:
[05:46:20]          File: /bin/netstat
[05:46:20]          Current hash: b013c213d8c408e72d4bebcb471c9ed2a76f976c6c2ff5c90b396332928b78f1
[05:46:21]          Stored hash : 8a0165cb4bf34d083ee755efee338dd9b8e1ccbe
[05:46:21]  /bin/ping                                      [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/ping
[05:46:21]          Current hash: 5249815d2afc2011df86ad95cb2990e4f225990c37372d5e0d6019085df7dee6
[05:46:21]          Stored hash : b78428f497b6ee2ebcfcde9dadbaeb78b71e8add
[05:46:21]  /bin/ps                                        [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/ps
[05:46:21]          Current hash: 7ba7fbc891e831b58e3267d74237a06dd9701501c36515dff74153b9b2a64a92
[05:46:21]          Stored hash : cf40ccb422af5a4a720866a07cdd393816f1f6e1
[05:46:21]  /bin/pwd                                        [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/pwd
[05:46:21]          Current hash: 8ad543e044f77020f4a8aeed95cd91a1bed4c759cc14cb1a517041ee8a6b0bc4
[05:46:21]          Stored hash : 53b3304ac61ae0e0dfc57e176bb09e0feded87f0
[05:46:21]  /bin/readlink                                  [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/readlink
[05:46:21]          Current hash: 61359b5a4dfa37408032b8903e80110c0ee163b3f563c770a7031c6a9f22066f
[05:46:21]          Stored hash : 05773d2729050a42bced99f2568564b24c88820f
[05:46:21]  /bin/sed                                        [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/sed
[05:46:21]          Current hash: e80ef105ffd7e023f685a6480e8cc72c60b0528ed3a9abe0ad74976669c9e265
[05:46:21]          Stored hash : 98f0ce777f57ddf69110600ca863286d15ff19e6
[05:46:21]  /bin/sh                                        [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/sh
[05:46:21]          Current hash: e865a4ff01b0df1afec7b5fd7b3a8906baa57d77daaa4888a31dccbf004d011b
[05:46:21]          Stored hash : 1f20b39898c7cf4768a2023276b419bcea142c34
[05:46:21]  /bin/su                                        [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/su
[05:46:21]          Current hash: bf143b29fbd67da0feb885a328d243bfc3c31c861ff71d74dab0608e41080007
[05:46:21]          Stored hash : 7e1f29a968867f2f61c60f6536454c8b2bc156f1
[05:46:21]  /bin/touch                                      [ Warning ]
[05:46:21] Warning: The file properties have changed:
[05:46:21]          File: /bin/touch
[05:46:21]          Current hash: 592bf9c6a1204f9a2adc782d410677c7eca3af1b8134caf85c54e1e9b75c39b9
[05:46:21]          Stored hash : 3d11398da75dcee8dc34204a5a4624e5ee45b5ea
[05:46:22]  /bin/uname                                      [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/uname
[05:46:22]          Current hash: 20cfebd591ce1d3d2b78c55fd022ea1a94d0aac6675b0f75c9ade9567274e1ec
[05:46:22]          Stored hash : 7e862cc56ef28f118c477f3a4937927be0b8de6a
[05:46:22]  /bin/which                                      [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/which
[05:46:22]          Current hash: 7bdde142dc5cb004ab82f55adba0c56fc78430a6f6b23afd33be491d4c7c238b
[05:46:22]          Stored hash : cd2cdf42c04fba4123f4b8f12bca9bbd76552c95
[05:46:22] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[05:46:22]  /bin/kmod                                      [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/kmod
[05:46:22]          Current hash: d5e40d5b77530f3053e7539f4704da5f38f52d79d3857070fc6a6c82fa0d4a3c
[05:46:22]          Stored hash : acc69ad1870f7d10c71886dd4b2602fbfb553d3e
[05:46:22]  /bin/systemd                                    [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/systemd
[05:46:22]          Current hash: 97089b739ae4727d312eff88901d5c088f29f72f878c8213112e41559e46bcf9
[05:46:22]          Stored hash : f27f7f1a84e12120e587148aa6e97c5545c7f909
[05:46:22]  /bin/systemctl                                  [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/systemctl
[05:46:22]          Current hash: 0cb19a37bc96d70bcdabae8f7723a6c74c376e367f91531a82254878759b9e9c
[05:46:22]          Stored hash : ff23fef9209eb18843944a2a68bccaecaeadbaf1
[05:46:22]  /bin/dash                                      [ Warning ]
[05:46:22] Warning: The file properties have changed:
[05:46:22]          File: /bin/dash
[05:46:22]          Current hash: e865a4ff01b0df1afec7b5fd7b3a8906baa57d77daaa4888a31dccbf004d011b
[05:46:22]          Stored hash : 1f20b39898c7cf4768a2023276b419bcea142c34
[05:46:23]  /lib/systemd/systemd                            [ Warning ]
[05:46:23] Warning: The file properties have changed:
[05:46:23]          File: /lib/systemd/systemd
[05:46:23]          Current hash: 97089b739ae4727d312eff88901d5c088f29f72f878c8213112e41559e46bcf9
[05:46:23]          Stored hash : f27f7f1a84e12120e587148aa6e97c5545c7f909
[05:46:24]
[05:46:24] Info: Starting test name 'rootkits'
[05:46:24] Checking for rootkits...
[05:46:24]
[05:46:24] Info: Starting test name 'known_rkts'
[05:46:24] Performing check of known rootkit files and directories
[05:46:24]
[05:46:24] Checking for 55808 Trojan - Variant A...
[05:46:24]  Checking for file '/tmp/.../r'                  [ Not found ]
[05:46:24]  Checking for file '/tmp/.../a'                  [ Not found ]
[05:46:24] 55808 Trojan - Variant A                          [ Not found ]
[05:46:24]
[05:46:24] Checking for ADM Worm...
[05:46:24]  Checking for string 'w0rm'                      [ Not found ]
[05:46:24] ADM Worm                                          [ Not found ]
[05:46:24]
[05:46:24] Checking for AjaKit Rootkit...
[05:46:24]  Checking for file '/dev/tux/.addr'              [ Not found ]
[05:46:24]  Checking for file '/dev/tux/.proc'              [ Not found ]
[05:46:24]  Checking for file '/dev/tux/.file'              [ Not found ]
[05:46:24]  Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[05:46:24]  Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[05:46:24]  Checking for file '/lib/.libgh-gh/sb0k'        [ Not found ]
[05:46:24]  Checking for directory '/dev/tux'              [ Not found ]
[05:46:24]  Checking for directory '/lib/.libgh-gh'        [ Not found ]
[05:46:24] AjaKit Rootkit                                    [ Not found ]
[05:46:24]
[05:46:24] Checking for Adore Rootkit...
[05:46:24]  Checking for file '/usr/secure'                [ Not found ]
[05:46:24]  Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[05:46:24]  Checking for file '/usr/doc/sys/run'            [ Not found ]
[05:46:24]  Checking for file '/usr/doc/sys/crond'          [ Not found ]
[05:46:24]  Checking for file '/usr/sbin/kfd'              [ Not found ]
[05:46:24]  Checking for file '/usr/doc/kern/var'          [ Not found ]
[05:46:24]  Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[05:46:24]  Checking for file '/usr/doc/kern/ava'          [ Not found ]
[05:46:24]  Checking for file '/usr/doc/kern/adore.o'      [ Not found ]
[05:46:24]  Checking for file '/var/log/ssh/old'            [ Not found ]
[05:46:24]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/kern'          [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/backup'        [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[05:46:24]  Checking for directory '/lib/backup'            [ Not found ]
[05:46:24]  Checking for directory '/lib/backup/txt'        [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/work'          [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/sys'          [ Not found ]
[05:46:24]  Checking for directory '/var/log/ssh'          [ Not found ]
[05:46:24]  Checking for directory '/usr/doc/.spool'        [ Not found ]
[05:46:24]  Checking for directory '/usr/lib/kterm'        [ Not found ]
[05:46:24] Adore Rootkit                                    [ Not found ]
[05:46:24]
[05:46:24] Checking for aPa Kit...
[05:46:24]  Checking for file '/usr/share/.aPa'            [ Not found ]
[05:46:24] aPa Kit                                          [ Not found ]
[05:46:24]
[05:46:24] Checking for Apache Worm...
[05:46:24]  Checking for file '/bin/.log'                  [ Not found ]
[05:46:24] Apache Worm                                      [ Not found ]
[05:46:24]
[05:46:24] Checking for Ambient (ark) Rootkit...
[05:46:24]  Checking for file '/usr/lib/.ark?'              [ Not found ]
[05:46:24]  Checking for file '/dev/ptyxx/.log'            [ Not found ]
[05:46:24]  Checking for file '/dev/ptyxx/.file'            [ Not found ]
[05:46:24]  Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[05:46:24]  Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[05:46:24]  Checking for directory '/dev/ptyxx'            [ Not found ]
[05:46:24] Ambient (ark) Rootkit                            [ Not found ]
[05:46:24]
[05:46:24] Checking for Balaur Rootkit...
[05:46:24]  Checking for file '/usr/lib/liblog.o'          [ Not found ]
[05:46:24]  Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[05:46:24]  Checking for directory '/usr/lib/.egcs'        [ Not found ]
[05:46:24]  Checking for directory '/usr/lib/.wormie'      [ Not found ]
[05:46:24] Balaur Rootkit                                    [ Not found ]
[05:46:24]
[05:46:24] Checking for BeastKit Rootkit...
[05:46:24]  Checking for file '/usr/sbin/arobia'            [ Not found ]
[05:46:24]  Checking for file '/usr/sbin/idrun'            [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm'    [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[05:46:24]  Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[05:46:24]  Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[05:46:24] BeastKit Rootkit                                  [ Not found ]
[05:46:25]
[05:46:25] Checking for beX2 Rootkit...
[05:46:25]  Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/sshd2'              [ Not found ]
[05:46:25]  Checking for directory '/usr/include/bex'      [ Not found ]
[05:46:25] beX2 Rootkit                                      [ Not found ]
[05:46:25]
[05:46:25] Checking for BOBKit Rootkit...
[05:46:25]  Checking for file '/usr/sbin/ntpsx'            [ Not found ]
[05:46:25]  Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[05:46:25]  Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[05:46:25]  Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[05:46:25]  Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../proc.h'    [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../.bash_history' [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../bkit-get'  [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[05:46:25]  Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-adore.o'  [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../ls'            [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../netstat'        [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../lsof'          [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../psr'            [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../find'          [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../pstree'        [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../slocate'        [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../du'            [ Not found ]
[05:46:25]  Checking for file '/usr/lib/.../top'            [ Not found ]
[05:46:25]  Checking for directory '/usr/sbin/...'          [ Not found ]
[05:46:25]  Checking for directory '/usr/include/...'      [ Not found ]
[05:46:25]  Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[05:46:25]  Checking for directory '/usr/lib/...'          [ Not found ]
[05:46:25]  Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[05:46:25]  Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[05:46:25]  Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[05:46:25]  Checking for directory '/tmp/.bkp'              [ Not found ]
[05:46:25] BOBKit Rootkit                                    [ Not found ]
[05:46:25]
[05:46:25] Checking for cb Rootkit...
[05:46:25]  Checking for file '/dev/srd0'                  [ Not found ]
[05:46:25]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[05:46:25]  Checking for file '/dev/mounnt'                [ Not found ]
[05:46:25]  Checking for file '/etc/rc.d/init.d/init'      [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/cl'    [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/wted'  [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/scan'  [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/sc'    [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/sl2'  [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/wu'    [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/v'    [ Not found ]
[05:46:25]  Checking for file '/usr/bin/.zeen/..<SP>/read'  [ Not found ]
[05:46:25]  Checking for file '/usr/lib/sshrc'              [ Not found ]
[05:46:25]  Checking for file '/usr/lib/ssh_host_key'      [ Not found ]
[05:46:25]  Checking for file '/usr/lib/ssh_host_key.pub'  [ Not found ]
[05:46:25]  Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[05:46:26]  Checking for file '/usr/lib/sshd_config'        [ Not found ]
[05:46:26]  Checking for file '/usr/lib/shosts.equiv'      [ Not found ]
[05:46:26]  Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[05:46:26]  Checking for file '/u/zappa/.ssh/pid'          [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[05:46:26]  Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[05:46:26]  Checking for directory '/usr/bin/.zeen'        [ Not found ]
[05:46:26]  Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[05:46:26]  Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[05:46:26]  Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[05:46:26] cb Rootkit                                        [ Not found ]
[05:46:26]
[05:46:26] Checking for CiNIK Worm (Slapper.B variant)...
[05:46:26]  Checking for file '/tmp/.cinik'                [ Not found ]
[05:46:26]  Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[05:46:26] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[05:46:26]
[05:46:26] Checking for Danny-Boy's Abuse Kit...
[05:46:26]  Checking for file '/dev/mdev'                  [ Not found ]
[05:46:26]  Checking for file '/usr/lib/libX.a'            [ Not found ]
[05:46:26] Danny-Boy's Abuse Kit                            [ Not found ]
[05:46:26]
[05:46:26] Checking for Devil RootKit...
[05:46:26]  Checking for file '/var/lib/games/.src'        [ Not found ]
[05:46:26]  Checking for file '/dev/dsx'                    [ Not found ]
[05:46:26]  Checking for file '/dev/caca'                  [ Not found ]
[05:46:26]  Checking for file '/dev/pro'                    [ Not found ]
[05:46:26]  Checking for file '/bin/bye'                    [ Not found ]
[05:46:26]  Checking for file '/bin/homedir'                [ Not found ]
[05:46:26]  Checking for file '/usr/bin/xfss'              [ Not found ]
[05:46:26]  Checking for file '/usr/sbin/tzava'            [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[05:46:26]  Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[05:46:26]  Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[05:46:26] Devil RootKit                                    [ Not found ]
[05:46:26]
[05:46:26] Checking for Dica-Kit Rootkit...
[05:46:26]  Checking for file '/lib/.sso'                  [ Not found ]
[05:46:26]  Checking for file '/lib/.so'                    [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/clean'      [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/dxr'        [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/read'      [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/write'      [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/lf'        [ Not found ]
[05:46:26]  Checking for file '/var/run/...dica/xl'        [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/xdr'        [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/psg'        [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/secure'    [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/rdx'        [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/va'        [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[05:46:27]  Checking for file '/var/run/...dica/last.log'  [ Not found ]
[05:46:27]  Checking for file '/usr/bin/.etc'              [ Not found ]
[05:46:27]  Checking for file '/etc/sshd_config'            [ Not found ]
[05:46:27]  Checking for file '/etc/ssh_host_key'          [ Not found ]
[05:46:27]  Checking for file '/etc/ssh_random_seed'        [ Not found ]
[05:46:27]  Checking for directory '/var/run/...dica'      [ Not found ]
[05:46:27]  Checking for directory '/var/run/...dica/mh'    [ Not found ]
[05:46:27]  Checking for directory '/var/run/...dica/scan'  [ Not found ]
[05:46:27] Dica-Kit Rootkit                                  [ Not found ]
[05:46:27]
[05:46:27] Checking for Dreams Rootkit...
[05:46:27]  Checking for file '/dev/ttyoa'                  [ Not found ]
[05:46:27]  Checking for file '/dev/ttyof'                  [ Not found ]
[05:46:27]  Checking for file '/dev/ttyop'                  [ Not found ]
[05:46:27]  Checking for file '/usr/bin/sense'              [ Not found ]
[05:46:27]  Checking for file '/usr/bin/sl2'                [ Not found ]
[05:46:27]  Checking for file '/usr/bin/logclear'          [ Not found ]
[05:46:27]  Checking for file '/usr/bin/(swapd)'            [ Not found ]
[05:46:27]  Checking for file '/usr/bin/initrd'            [ Not found ]
[05:46:27]  Checking for file '/usr/bin/crontabs'          [ Not found ]
[05:46:27]  Checking for file '/usr/bin/snfs'              [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libsss'            [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libsnf.log'        [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libshtift/top'      [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libshtift/ps'      [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libshtift/netstat'  [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libshtift/ls'      [ Not found ]
[05:46:27]  Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[05:46:27]  Checking for file '/usr/include/linseed.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/linpid.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/linkey.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/linconf.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/iceseed.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/icepid.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/icekey.h'      [ Not found ]
[05:46:27]  Checking for file '/usr/include/iceconf.h'      [ Not found ]
[05:46:27]  Checking for directory '/dev/ida/.hpd'          [ Not found ]
[05:46:27]  Checking for directory '/usr/lib/libshtift'    [ Not found ]
[05:46:27] Dreams Rootkit                                    [ Not found ]
[05:46:27]
[05:46:27] Checking for Duarawkz Rootkit...
[05:46:27]  Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[05:46:27]  Checking for directory '/usr/bin/duarawkz'      [ Not found ]
[05:46:27] Duarawkz Rootkit                                  [ Not found ]
[05:46:27]
[05:46:27] Checking for Enye LKM...
[05:46:27]  Checking for file '/etc/.enyelkmHIDE^IT.ko'    [ Not found ]
[05:46:27]  Checking for file '/etc/.enyelkmOCULTAR.ko'    [ Not found ]
[05:46:27] Enye LKM                                          [ Not found ]
[05:46:27]
[05:46:27] Checking for Flea Linux Rootkit...
[05:46:27]  Checking for file '/etc/ld.so.hash'            [ Not found ]
[05:46:27]  Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[05:46:27]  Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[05:46:27]  Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[05:46:27]  Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[05:46:27]  Checking for file '/usr/bin/ssh2d'              [ Not found ]
[05:46:27]  Checking for file '/usr/lib/ldlibns.so'        [ Not found ]
[05:46:27]  Checking for file '/usr/lib/ldlibps.so'        [ Not found ]
[05:46:27]  Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
[05:46:27]  Checking for file '/usr/lib/ldlibdu.so'        [ Not found ]
[05:46:27]  Checking for file '/usr/lib/ldlibct.so'        [ Not found ]
[05:46:27]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[05:46:27]  Checking for directory '/dev/..0'              [ Not found ]
[05:46:27]  Checking for directory '/dev/..0/backup'        [ Not found ]
[05:46:27] Flea Linux Rootkit                                [ Not found ]
[05:46:27]
[05:46:27] Checking for Fu Rootkit...
[05:46:27]  Checking for file '/sbin/xc'                    [ Not found ]
[05:46:27]  Checking for file '/usr/include/ivtype.h'      [ Not found ]
[05:46:27]  Checking for file '/bin/.lib'                  [ Not found ]
[05:46:27] Fu Rootkit                                        [ Not found ]
[05:46:28]
[05:46:28] Checking for Fuck`it Rootkit...
[05:46:28]  Checking for file '/lib/libproc.so.2.0.7'      [ Not found ]
[05:46:28]  Checking for file '/dev/proc/.bash_profile'    [ Not found ]
[05:46:28]  Checking for file '/dev/proc/.bashrc'          [ Not found ]
[05:46:28]  Checking for file '/dev/proc/.cshrc'            [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/hax0r'      [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[05:46:28]  Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[05:46:28]  Checking for file '/usr/lib/libcps.a'          [ Not found ]
[05:46:28]  Checking for file '/usr/lib/libtty.a'          [ Not found ]
[05:46:28]  Checking for directory '/dev/proc'              [ Not found ]
[05:46:28]  Checking for directory '/dev/proc/fuckit'      [ Not found ]
[05:46:28]  Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[05:46:28]  Checking for directory '/dev/proc/toolz'        [ Not found ]
[05:46:28] Fuck`it Rootkit                                  [ Not found ]
[05:46:28]
[05:46:28] Checking for GasKit Rootkit...
[05:46:28]  Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
[05:46:28]  Checking for directory '/dev/dev'              [ Not found ]
[05:46:28]  Checking for directory '/dev/dev/gaskit'        [ Not found ]
[05:46:28]  Checking for directory '/dev/dev/gaskit/sshd'  [ Not found ]
[05:46:28] GasKit Rootkit                                    [ Not found ]
[05:46:28]
[05:46:28] Checking for Heroin LKM...
[05:46:28]  Checking for kernel symbol 'heroin'            [ Not found ]
[05:46:28] Heroin LKM                                        [ Not found ]
[05:46:28]
[05:46:28] Checking for HjC Kit...
[05:46:28]  Checking for directory '/dev/.hijackerz'        [ Not found ]
[05:46:28] HjC Kit                                          [ Not found ]
[05:46:28]
[05:46:28] Checking for ignoKit Rootkit...
[05:46:28]  Checking for file '/lib/defs/p'                [ Not found ]
[05:46:28]  Checking for file '/lib/defs/q'                [ Not found ]
[05:46:28]  Checking for file '/lib/defs/r'                [ Not found ]
[05:46:28]  Checking for file '/lib/defs/s'                [ Not found ]
[05:46:28]  Checking for file '/lib/defs/t'                [ Not found ]
[05:46:28]  Checking for file '/usr/lib/defs/p'            [ Not found ]
[05:46:28]  Checking for file '/usr/lib/defs/q'            [ Not found ]
[05:46:28]  Checking for file '/usr/lib/defs/r'            [ Not found ]
[05:46:28]  Checking for file '/usr/lib/defs/s'            [ Not found ]
[05:46:28]  Checking for file '/usr/lib/defs/t'            [ Not found ]
[05:46:28]  Checking for file '/usr/lib/.libigno/pkunsec'  [ Not found ]
[05:46:28]  Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[05:46:28]  Checking for directory '/usr/lib/.libigno'      [ Not found ]
[05:46:28]  Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[05:46:28] ignoKit Rootkit                                  [ Not found ]
[05:46:28]
[05:46:28] Checking for IntoXonia-NG Rootkit...
[05:46:28]  Checking for kernel symbol 'funces'            [ Not found ]
[05:46:29]  Checking for kernel symbol 'ixinit'            [ Not found ]
[05:46:29]  Checking for kernel symbol 'tricks'            [ Not found ]
[05:46:29]  Checking for kernel symbol 'kernel_unlink'      [ Not found ]
[05:46:29]  Checking for kernel symbol 'rootme'            [ Not found ]
[05:46:29]  Checking for kernel symbol 'hide_module'        [ Not found ]
[05:46:29]  Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
[05:46:29] IntoXonia-NG Rootkit                              [ Not found ]
[05:46:29]
[05:46:29] Checking for Irix Rootkit...
[05:46:29]  Checking for directory '/dev/pts/01'            [ Not found ]
[05:46:29]  Checking for directory '/dev/pts/01/backup'    [ Not found ]
[05:46:29]  Checking for directory '/dev/pts/01/etc'        [ Not found ]
[05:46:29]  Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[05:46:29] Irix Rootkit                                      [ Not found ]
[05:46:29]
[05:46:29] Checking for Jynx Rootkit...
[05:46:29]  Checking for file '/xochikit/bc'                [ Not found ]
[05:46:29]  Checking for file '/xochikit/ld_poison.so'      [ Not found ]
[05:46:29]  Checking for file '/omgxochi/bc'                [ Not found ]
[05:46:29]  Checking for file '/omgxochi/ld_poison.so'      [ Not found ]
[05:46:29]  Checking for file '/var/local/^^/bc'            [ Not found ]
[05:46:29]  Checking for file '/var/local/^^/ld_poison.so'  [ Not found ]
[05:46:29]  Checking for directory '/xochikit'              [ Not found ]
[05:46:29]  Checking for directory '/omgxochi'              [ Not found ]
[05:46:29]  Checking for directory '/var/local/^^'          [ Not found ]
[05:46:29] Jynx Rootkit                                      [ Not found ]
[05:46:29]
[05:46:29] Checking for KBeast Rootkit...
[05:46:29]  Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[05:46:29]  Checking for file '/usr/_h4x_/_h4x_bd'          [ Not found ]
[05:46:29]  Checking for file '/usr/_h4x_/acctlog'          [ Not found ]
[05:46:29]  Checking for directory '/usr/_h4x_'            [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_delete_module'  [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_getdents64'    [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_kill'          [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_open'          [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_read'          [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_rename'        [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_rmdir'          [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_tcp4_seq_show'  [ Not found ]
[05:46:30]  Checking for kernel symbol 'h4x_write'          [ Not found ]
[05:46:30] KBeast Rootkit                                    [ Not found ]
[05:46:30]
[05:46:30] Checking for Kitko Rootkit...
[05:46:30]  Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[05:46:30] Kitko Rootkit                                    [ Not found ]
[05:46:30]
[05:46:30] Checking for Knark Rootkit...
[05:46:30]  Checking for file '/proc/knark/pids'            [ Not found ]
[05:46:30]  Checking for directory '/proc/knark'            [ Not found ]
[05:46:30] Knark Rootkit                                    [ Not found ]
[05:46:30]
[05:46:30] Checking for ld-linuxv.so Rootkit...
[05:46:30]  Checking for file '/lib/ld-linuxv.so.1'        [ Not found ]
[05:46:30]  Checking for directory '/var/opt/_so_cache'    [ Not found ]
[05:46:30]  Checking for directory '/var/opt/_so_cache/ld'  [ Not found ]
[05:46:30]  Checking for directory '/var/opt/_so_cache/lc'  [ Not found ]
[05:46:30] ld-linuxv.so Rootkit                              [ Not found ]
[05:46:30]
[05:46:30] Checking for Li0n Worm...
[05:46:30]  Checking for file '/bin/in.telnetd'            [ Not found ]
[05:46:30]  Checking for file '/bin/mjy'                    [ Not found ]
[05:46:30]  Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[05:46:30]  Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[05:46:30]  Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/bind'    [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/1i0n.sh'      [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/lib/netstat'  [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[05:46:30]  Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[05:46:30] Li0n Worm                                        [ Not found ]
[05:46:30]
[05:46:30] Checking for Lockit / LJK2 Rootkit...
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[05:46:30]  Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[05:46:31]  Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[05:46:31]  Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[05:46:31] Lockit / LJK2 Rootkit                            [ Not found ]
[05:46:31]
[05:46:31] Checking for Mood-NT Rootkit...
[05:46:31]  Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[05:46:31]  Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[05:46:31]  Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[05:46:31]  Checking for file '/_cthulhu/mood-nt.sniff'    [ Not found ]
[05:46:31]  Checking for directory '/_cthulhu'              [ Not found ]
[05:46:31] Mood-NT Rootkit                                  [ Not found ]
[05:46:31]
[05:46:31] Checking for MRK Rootkit...
[05:46:31]  Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[05:46:31]  Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[05:46:31]  Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[05:46:31]  Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[05:46:31]  Checking for directory '/dev/ida/.inet'        [ Not found ]
[05:46:31]  Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[05:46:31] MRK Rootkit                                      [ Not found ]


dennisstein 16.04.2016 02:23

RKHunter Teil 2

Code:

[05:46:31]
[05:46:31] Checking for Ni0 Rootkit...
[05:46:31]  Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[05:46:31]  Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[05:46:31]  Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[05:46:31]  Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[05:46:31]  Checking for directory '/tmp/waza'              [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[05:46:31]  Checking for directory '/usr/sbin/es'          [ Not found ]
[05:46:31] Ni0 Rootkit                                      [ Not found ]
[05:46:31]
[05:46:31] Checking for Ohhara Rootkit...
[05:46:31]  Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[05:46:31]  Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[05:46:31] Ohhara Rootkit                                    [ Not found ]
[05:46:31]
[05:46:31] Checking for Optic Kit (Tux) Worm...
[05:46:31]  Checking for directory '/dev/tux'              [ Not found ]
[05:46:31]  Checking for directory '/usr/bin/xchk'          [ Not found ]
[05:46:31]  Checking for directory '/usr/bin/xsf'          [ Not found ]
[05:46:31]  Checking for directory '/usr/bin/ssh2d'        [ Not found ]
[05:46:31] Optic Kit (Tux) Worm                              [ Not found ]
[05:46:31]
[05:46:31] Checking for Oz Rootkit...
[05:46:31]  Checking for file '/dev/.oz/.nap/rkit/terror'  [ Not found ]
[05:46:31]  Checking for directory '/dev/.oz'              [ Not found ]
[05:46:31] Oz Rootkit                                        [ Not found ]
[05:46:31]
[05:46:31] Checking for Phalanx Rootkit...
[05:46:31]  Checking for file '/uNFuNF'                    [ Not found ]
[05:46:31]  Checking for file '/etc/host.ph1'              [ Not found ]
[05:46:31]  Checking for file '/bin/host.ph1'              [ Not found ]
[05:46:31]  Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[05:46:31]  Checking for file '/usr/share/.home.ph1/cb'    [ Not found ]
[05:46:31]  Checking for file '/usr/share/.home.ph1/kebab'  [ Not found ]
[05:46:31]  Checking for directory '/usr/share/.home.ph1'  [ Not found ]
[05:46:31]  Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[05:46:31] Phalanx Rootkit                                  [ Not found ]
[05:46:31]
[05:46:31] Checking for Phalanx2 Rootkit...
[05:46:31]  Checking for file '/etc/khubd.p2/.p2rc'        [ Not found ]
[05:46:32]  Checking for file '/etc/khubd.p2/.phalanx2'    [ Not found ]
[05:46:32]  Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
[05:46:32]  Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
[05:46:32]  Checking for file '/etc/lolzz.p2/.p2rc'        [ Not found ]
[05:46:32]  Checking for file '/etc/lolzz.p2/.phalanx2'    [ Not found ]
[05:46:32]  Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
[05:46:32]  Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
[05:46:32]  Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[05:46:32]  Checking for file '/usr/lib/zupzz.p2/.p-2.3d'  [ Not found ]
[05:46:32]  Checking for file '/usr/lib/zupzz.p2/.p2rc'    [ Not found ]
[05:46:32]  Checking for directory '/etc/khubd.p2'          [ Not found ]
[05:46:32]  Checking for directory '/etc/lolzz.p2'          [ Not found ]
[05:46:32]  Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[05:46:32] Phalanx2 Rootkit                                  [ Not found ]
[05:46:32]
[05:46:32] Checking for Phalanx2 Rootkit (extended tests)...
[05:46:32]  Checking for directory '/etc/khubd.p2'          [ Not found ]
[05:46:32]  Checking for directory '/etc/lolzz.p2'          [ Not found ]
[05:46:32]  Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[05:46:32] Phalanx2 Rootkit (extended tests)                [ Not found ]
[05:46:32]
[05:46:32] Checking for Portacelo Rootkit...
[05:46:32]  Checking for file '/var/lib/.../.ak'            [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../.hk'            [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../.rs'            [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../.p'            [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../getty'          [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../show'          [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../nlkt.o'        [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../ssshrc'        [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../sssh_equiv'    [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[05:46:32]  Checking for file '/var/lib/.../sssh_pid'      [ Not found ]
[05:46:32]  Checking for file '~/.sssh/known_hosts'        [ Not found ]
[05:46:32] Portacelo Rootkit                                [ Not found ]
[05:46:32]
[05:46:32] Checking for R3dstorm Toolkit...
[05:46:32]  Checking for file '/var/log/tk02/see_all'      [ Not found ]
[05:46:32]  Checking for file '/var/log/tk02/.scris'        [ Not found ]
[05:46:32]  Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[05:46:32]  Checking for file '/bin/.../hate/sk'            [ Not found ]
[05:46:32]  Checking for file '/bin/.../see_all'            [ Not found ]
[05:46:32]  Checking for directory '/var/log/tk02'          [ Not found ]
[05:46:32]  Checking for directory '/var/log/tk02/old'      [ Not found ]
[05:46:32]  Checking for directory '/bin/...'              [ Not found ]
[05:46:32] R3dstorm Toolkit                                  [ Not found ]
[05:46:32]
[05:46:32] Checking for RH-Sharpe's Rootkit...
[05:46:32]  Checking for file '/bin/lps'                    [ Not found ]
[05:46:32]  Checking for file '/usr/bin/lpstree'            [ Not found ]
[05:46:32]  Checking for file '/usr/bin/ltop'              [ Not found ]
[05:46:32]  Checking for file '/usr/bin/lkillall'          [ Not found ]
[05:46:32]  Checking for file '/usr/bin/ldu'                [ Not found ]
[05:46:32]  Checking for file '/usr/bin/lnetstat'          [ Not found ]
[05:46:32]  Checking for file '/usr/bin/wp'                [ Not found ]
[05:46:32]  Checking for file '/usr/bin/shad'              [ Not found ]
[05:46:32]  Checking for file '/usr/bin/vadim'              [ Not found ]
[05:46:32]  Checking for file '/usr/bin/slice'              [ Not found ]
[05:46:32]  Checking for file '/usr/bin/cleaner'            [ Not found ]
[05:46:32]  Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[05:46:32] RH-Sharpe's Rootkit                              [ Not found ]
[05:46:32]
[05:46:32] Checking for RSHA's Rootkit...
[05:46:32]  Checking for file '/bin/kr4p'                  [ Not found ]
[05:46:32]  Checking for file '/usr/bin/n3tstat'            [ Not found ]
[05:46:32]  Checking for file '/usr/bin/chsh2'              [ Not found ]
[05:46:32]  Checking for file '/usr/bin/slice2'            [ Not found ]
[05:46:32]  Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[05:46:32]  Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[05:46:32]  Checking for directory '/etc/rc.d/rsha'        [ Not found ]
[05:46:32]  Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[05:46:32] RSHA's Rootkit                                    [ Not found ]
[05:46:32]
[05:46:32] Checking for Scalper Worm...
[05:46:32]  Checking for file '/tmp/.a'                    [ Not found ]
[05:46:32]  Checking for file '/tmp/.uua'                  [ Not found ]
[05:46:32] Scalper Worm                                      [ Not found ]
[05:46:32]
[05:46:32] Checking for Sebek LKM...
[05:46:32]  Checking for kernel symbol 'adore or sebek'    [ Not found ]
[05:46:32] Sebek LKM                                        [ Not found ]
[05:46:32]
[05:46:32] Checking for Shutdown Rootkit...
[05:46:32]  Checking for file '/usr/man/man5/..<SP>/.dir/scannah/asus' [ Not found ]
[05:46:33]  Checking for file '/usr/man/man5/..<SP>/.dir/see' [ Not found ]
[05:46:33]  Checking for file '/usr/man/man5/..<SP>/.dir/nscd' [ Not found ]
[05:46:33]  Checking for file '/usr/man/man5/..<SP>/.dir/alpd' [ Not found ]
[05:46:33]  Checking for file '/etc/rc.d/rc.local<SP>'      [ Not found ]
[05:46:33]  Checking for directory '/usr/man/man5/..<SP>/.dir' [ Not found ]
[05:46:33]  Checking for directory '/usr/man/man5/..<SP>/.dir/scannah' [ Not found ]
[05:46:33]  Checking for directory '/etc/rc.d/rc0.d/..<SP>/.dir' [ Not found ]
[05:46:33] Shutdown Rootkit                                  [ Not found ]
[05:46:33]
[05:46:33] Checking for SHV4 Rootkit...
[05:46:33]  Checking for file '/etc/ld.so.hash'            [ Not found ]
[05:46:33]  Checking for file '/lib/libext-2.so.7'          [ Not found ]
[05:46:33]  Checking for file '/lib/lidps1.so'              [ Not found ]
[05:46:33]  Checking for file '/lib/libproc.a'              [ Not found ]
[05:46:33]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[05:46:33]  Checking for file '/lib/ldd.so/tks'            [ Not found ]
[05:46:33]  Checking for file '/lib/ldd.so/tkp'            [ Not found ]
[05:46:33]  Checking for file '/lib/ldd.so/tksb'            [ Not found ]
[05:46:33]  Checking for file '/lib/security/.config/sshd'  [ Not found ]
[05:46:33]  Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[05:46:33]  Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[05:46:33]  Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[05:46:33]  Checking for file '/usr/include/file.h'        [ Not found ]
[05:46:33]  Checking for file '/usr/include/hosts.h'        [ Not found ]
[05:46:33]  Checking for file '/usr/include/lidps1.so'      [ Not found ]
[05:46:33]  Checking for file '/usr/include/log.h'          [ Not found ]
[05:46:33]  Checking for file '/usr/include/proc.h'        [ Not found ]
[05:46:33]  Checking for file '/usr/sbin/xntps'            [ Not found ]
[05:46:33]  Checking for file '/dev/srd0'                  [ Not found ]
[05:46:33]  Checking for directory '/lib/ldd.so'            [ Not found ]
[05:46:33]  Checking for directory '/lib/security/.config'  [ Not found ]
[05:46:33]  Checking for directory '/lib/security/.config/ssh' [ Not found ]
[05:46:33] SHV4 Rootkit                                      [ Not found ]
[05:46:33]
[05:46:33] Checking for SHV5 Rootkit...
[05:46:33]  Checking for file '/etc/sh.conf'                [ Not found ]
[05:46:33]  Checking for file '/lib/libproc.a'              [ Not found ]
[05:46:33]  Checking for file '/lib/libproc.so.2.0.6'      [ Not found ]
[05:46:33]  Checking for file '/lib/lidps1.so'              [ Not found ]
[05:46:33]  Checking for file '/lib/libsh.so/bash'          [ Not found ]
[05:46:33]  Checking for file '/usr/include/file.h'        [ Not found ]
[05:46:33]  Checking for file '/usr/include/hosts.h'        [ Not found ]
[05:46:33]  Checking for file '/usr/include/log.h'          [ Not found ]
[05:46:33]  Checking for file '/usr/include/proc.h'        [ Not found ]
[05:46:33]  Checking for file '/lib/libsh.so/shdcf2'        [ Not found ]
[05:46:33]  Checking for file '/lib/libsh.so/shhk'          [ Not found ]
[05:46:33]  Checking for file '/lib/libsh.so/shhk.pub'      [ Not found ]
[05:46:33]  Checking for file '/lib/libsh.so/shrs'          [ Not found ]
[05:46:33]  Checking for file '/usr/lib/libsh/.bashrc'      [ Not found ]
[05:46:33]  Checking for file '/usr/lib/libsh/shsb'        [ Not found ]
[05:46:33]  Checking for file '/usr/lib/libsh/hide'        [ Not found ]
[05:46:33]  Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[05:46:33]  Checking for file '/usr/lib/libsh/.sniff/shp'  [ Not found ]
[05:46:33]  Checking for file '/dev/srd0'                  [ Not found ]
[05:46:33]  Checking for directory '/lib/libsh.so'          [ Not found ]
[05:46:33]  Checking for directory '/usr/lib/libsh'        [ Not found ]
[05:46:33]  Checking for directory '/usr/lib/libsh/utilz'  [ Not found ]
[05:46:33]  Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[05:46:33] SHV5 Rootkit                                      [ Not found ]
[05:46:33]
[05:46:33] Checking for Sin Rootkit...
[05:46:33]  Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[05:46:33]  Checking for file '/dev/ttyoa'                  [ Not found ]
[05:46:33]  Checking for file '/dev/ttyof'                  [ Not found ]
[05:46:33]  Checking for file '/dev/ttyop'                  [ Not found ]
[05:46:33]  Checking for file '/dev/ttyos'                  [ Not found ]
[05:46:33]  Checking for file '/usr/lib/.lib'              [ Not found ]
[05:46:33]  Checking for file '/usr/lib/sn/.X'              [ Not found ]
[05:46:33]  Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[05:46:33]  Checking for file '/usr/lib/ld/.X'              [ Not found ]
[05:46:33]  Checking for file '/usr/man/man1/...'          [ Not found ]
[05:46:33]  Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[05:46:33]  Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[05:46:33]  Checking for directory '/usr/lib/sn'            [ Not found ]
[05:46:33]  Checking for directory '/usr/lib/man1/...'      [ Not found ]
[05:46:33]  Checking for directory '/dev/.haos'            [ Not found ]
[05:46:33] Sin Rootkit                                      [ Not found ]
[05:46:33]
[05:46:33] Checking for Slapper Worm...
[05:46:33]  Checking for file '/tmp/.bugtraq'              [ Not found ]
[05:46:33]  Checking for file '/tmp/.uubugtraq'            [ Not found ]
[05:46:33]  Checking for file '/tmp/.bugtraq.c'            [ Not found ]
[05:46:33]  Checking for file '/tmp/httpd'                  [ Not found ]
[05:46:33]  Checking for file '/tmp/.unlock'                [ Not found ]
[05:46:33]  Checking for file '/tmp/update'                [ Not found ]
[05:46:33]  Checking for file '/tmp/.cinik'                [ Not found ]
[05:46:33]  Checking for file '/tmp/.b'                    [ Not found ]
[05:46:34] Slapper Worm                                      [ Not found ]
[05:46:34]
[05:46:34] Checking for Sneakin Rootkit...
[05:46:34]  Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[05:46:34] Sneakin Rootkit                                  [ Not found ]
[05:46:34]
[05:46:34] Checking for 'Spanish' Rootkit...
[05:46:34]  Checking for file '/dev/ptyq'                  [ Not found ]
[05:46:34]  Checking for file '/bin/ad'                    [ Not found ]
[05:46:34]  Checking for file '/bin/ava'                    [ Not found ]
[05:46:34]  Checking for file '/bin/server'                [ Not found ]
[05:46:34]  Checking for file '/usr/sbin/rescue'            [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../chrps'        [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../chrifconfig'  [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../netstat'      [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../linsniffer'  [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../charbd'      [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../charbd2'      [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../charbd3'      [ Not found ]
[05:46:34]  Checking for file '/usr/share/.../charbd4'      [ Not found ]
[05:46:34]  Checking for file '/usr/man/tmp/update.tgz'    [ Not found ]
[05:46:34]  Checking for file '/var/lib/rpm/db.rpm'        [ Not found ]
[05:46:34]  Checking for file '/var/cache/man/.cat'        [ Not found ]
[05:46:34]  Checking for file '/var/spool/lpd/remote/.lpq'  [ Not found ]
[05:46:34]  Checking for directory '/usr/share/...'        [ Not found ]
[05:46:34] 'Spanish' Rootkit                                [ Not found ]
[05:46:34]
[05:46:34] Checking for Suckit Rootkit...
[05:46:34]  Checking for file '/sbin/initsk12'              [ Not found ]
[05:46:34]  Checking for file '/sbin/initxrk'              [ Not found ]
[05:46:34]  Checking for file '/usr/bin/null'              [ Not found ]
[05:46:34]  Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[05:46:34]  Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[05:46:34]  Checking for directory '/etc/.MG'              [ Not found ]
[05:46:34]  Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[05:46:34]  Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[05:46:34] Suckit Rootkit                                    [ Not found ]
[05:46:34]
[05:46:34] Checking for Superkit Rootkit...
[05:46:34]  Checking for file '/usr/man/.sman/sk/backsh'    [ Not found ]
[05:46:34]  Checking for file '/usr/man/.sman/sk/izbtrag'  [ Not found ]
[05:46:34]  Checking for file '/usr/man/.sman/sk/sksniff'  [ Not found ]
[05:46:34]  Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[05:46:34]  Checking for directory '/usr/man/.sman/sk'      [ Not found ]
[05:46:34] Superkit Rootkit                                  [ Not found ]
[05:46:34]
[05:46:34] Checking for TBD (Telnet BackDoor)...
[05:46:34]  Checking for file '/usr/lib/.tbd'              [ Not found ]
[05:46:34] TBD (Telnet BackDoor)                            [ Not found ]
[05:46:34]
[05:46:34] Checking for TeLeKiT Rootkit...
[05:46:34]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[05:46:34]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[05:46:34]  Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[05:46:34]  Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[05:46:34]  Checking for file '/dev/ptyr'                  [ Not found ]
[05:46:34]  Checking for file '/dev/ptyp'                  [ Not found ]
[05:46:34]  Checking for file '/dev/ptyq'                  [ Not found ]
[05:46:34]  Checking for file '/dev/hda06'                  [ Not found ]
[05:46:34]  Checking for file '/usr/info/libc1.so'          [ Not found ]
[05:46:34]  Checking for directory '/usr/man/man3/...'      [ Not found ]
[05:46:34]  Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[05:46:34]  Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[05:46:34] TeLeKiT Rootkit                                  [ Not found ]
[05:46:34]
[05:46:34] Checking for T0rn Rootkit...
[05:46:34]  Checking for file '/dev/.lib/lib/lib/t0rns'    [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/t0rnp'    [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/ssh.tgz'  [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/top'      [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/login'    [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/1i0n.sh'  [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[05:46:34]  Checking for file '/dev/.lib/lib/lib/mjy'      [ Not found ]
[05:46:35]  Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[05:46:35]  Checking for file '/dev/.lib/lib/lib/tfn'      [ Not found ]
[05:46:35]  Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[05:46:35]  Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[05:46:35]  Checking for file '/usr/info/.torn/sh*'        [ Not found ]
[05:46:35]  Checking for file '/usr/src/.puta/.1addr'      [ Not found ]
[05:46:35]  Checking for file '/usr/src/.puta/.1file'      [ Not found ]
[05:46:35]  Checking for file '/usr/src/.puta/.1proc'      [ Not found ]
[05:46:35]  Checking for file '/usr/src/.puta/.1logz'      [ Not found ]
[05:46:35]  Checking for file '/usr/info/.t0rn'            [ Not found ]
[05:46:35]  Checking for directory '/dev/.lib'              [ Not found ]
[05:46:35]  Checking for directory '/dev/.lib/lib'          [ Not found ]
[05:46:35]  Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[05:46:35]  Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[05:46:35]  Checking for directory '/dev/.lib/lib/scan'    [ Not found ]
[05:46:35]  Checking for directory '/usr/src/.puta'        [ Not found ]
[05:46:35]  Checking for directory '/usr/man/man1/man1'    [ Not found ]
[05:46:35]  Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[05:46:35]  Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[05:46:35]  Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[05:46:35] T0rn Rootkit                                      [ Not found ]
[05:46:35]
[05:46:35] Checking for trNkit Rootkit...
[05:46:35]  Checking for file '/usr/lib/libbins.la'        [ Not found ]
[05:46:35]  Checking for file '/usr/lib/libtcs.so'          [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/ulogin.sh'        [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/tcpshell.sh'      [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/bupdu'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/buloc'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/buloc1'          [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/buloc2'          [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/stat'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/backps'          [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/tree'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/topk'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/wold'            [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/whoold'          [ Not found ]
[05:46:35]  Checking for file '/dev/.ttpy/backdoors'        [ Not found ]
[05:46:35] trNkit Rootkit                                    [ Not found ]
[05:46:35]
[05:46:35] Checking for Trojanit Kit...
[05:46:35]  Checking for file '/bin/.ls'                    [ Not found ]
[05:46:35]  Checking for file '/bin/.ps'                    [ Not found ]
[05:46:35]  Checking for file '/bin/.netstat'              [ Not found ]
[05:46:35]  Checking for file '/usr/bin/.nop'              [ Not found ]
[05:46:35]  Checking for file '/usr/bin/.who'              [ Not found ]
[05:46:35] Trojanit Kit                                      [ Not found ]
[05:46:35]
[05:46:35] Checking for Tuxtendo Rootkit...
[05:46:35]  Checking for file '/lib/libproc.so.2.0.7'      [ Not found ]
[05:46:35]  Checking for file '/usr/bin/xchk'              [ Not found ]
[05:46:35]  Checking for file '/usr/bin/xsf'                [ Not found ]
[05:46:35]  Checking for file '/dev/tux/suidsh'            [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.addr'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.cron'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.file'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.log'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.proc'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.iface'            [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.pw'                [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.df'                [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.ssh'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/.tux'              [ Not found ]
[05:46:35]  Checking for file '/dev/tux/ssh2/sshd2_config'  [ Not found ]
[05:46:35]  Checking for file '/dev/tux/ssh2/hostkey'      [ Not found ]
[05:46:35]  Checking for file '/dev/tux/ssh2/hostkey.pub'  [ Not found ]
[05:46:35]  Checking for file '/dev/tux/ssh2/logo'          [ Not found ]
[05:46:35]  Checking for file '/dev/tux/ssh2/random_seed'  [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/crontab'    [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/df'          [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/dir'        [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/find'        [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/locate'      [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/netstat'    [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/ps'          [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/syslogd'    [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/top'        [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[05:46:35]  Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[05:46:36]  Checking for directory '/dev/tux'              [ Not found ]
[05:46:36]  Checking for directory '/dev/tux/ssh2'          [ Not found ]
[05:46:36]  Checking for directory '/dev/tux/backup'        [ Not found ]
[05:46:36] Tuxtendo Rootkit                                  [ Not found ]
[05:46:36]
[05:46:36] Checking for URK Rootkit...
[05:46:36]  Checking for file '/dev/prom/sn.l'              [ Not found ]
[05:46:36]  Checking for file '/usr/lib/ldlibps.so'        [ Not found ]
[05:46:36]  Checking for file '/usr/lib/ldlibnet.so'        [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/uconf.inv'      [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/cleaner'        [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/psniff'      [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/du'          [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/ls'          [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/passwd'      [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/ps'          [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/psr'        [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/su'          [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/find'        [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/netstat'    [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/ping'        [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/strings'    [ Not found ]
[05:46:36]  Checking for file '/dev/pts/01/bin/bash'        [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/ls'  [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/su'  [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[05:46:36]  Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[05:46:36]  Checking for file '/tmp/conf.inv'              [ Not found ]
[05:46:36]  Checking for directory '/dev/prom'              [ Not found ]
[05:46:36]  Checking for directory '/dev/pts/01'            [ Not found ]
[05:46:36]  Checking for directory '/dev/pts/01/bin'        [ Not found ]
[05:46:36]  Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[05:46:36] URK Rootkit                                      [ Not found ]
[05:46:36]
[05:46:36] Checking for Vampire Rootkit...
[05:46:36]  Checking for kernel symbol 'new_getdents'      [ Not found ]
[05:46:36]  Checking for kernel symbol 'old_getdents'      [ Not found ]
[05:46:36]  Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[05:46:36]  Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[05:46:36] Vampire Rootkit                                  [ Not found ]
[05:46:36]
[05:46:36] Checking for VcKit Rootkit...
[05:46:36]  Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[05:46:36]  Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[05:46:36] VcKit Rootkit                                    [ Not found ]
[05:46:36]
[05:46:36] Checking for Volc Rootkit...
[05:46:36]  Checking for file '/usr/bin/volc'              [ Not found ]
[05:46:36]  Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[05:46:36]  Checking for file '/usr/lib/volc/linsniff'      [ Not found ]
[05:46:36]  Checking for file '/etc/rc.d/rc1.d/S25sysconf'  [ Not found ]
[05:46:36]  Checking for file '/etc/rc.d/rc2.d/S25sysconf'  [ Not found ]
[05:46:36]  Checking for file '/etc/rc.d/rc3.d/S25sysconf'  [ Not found ]
[05:46:36]  Checking for file '/etc/rc.d/rc4.d/S25sysconf'  [ Not found ]
[05:46:36]  Checking for file '/etc/rc.d/rc5.d/S25sysconf'  [ Not found ]
[05:46:36]  Checking for directory '/var/spool/.recent'    [ Not found ]
[05:46:36]  Checking for directory '/var/spool/.recent/.files' [ Not found ]
[05:46:36]  Checking for directory '/usr/lib/volc'          [ Not found ]
[05:46:36]  Checking for directory '/usr/lib/volc/backup'  [ Not found ]
[05:46:36] Volc Rootkit                                      [ Not found ]
[05:46:36]
[05:46:36] Checking for Xzibit Rootkit...
[05:46:36]  Checking for file '/dev/dsx'                    [ Not found ]
[05:46:36]  Checking for file '/dev/caca'                  [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/linsniffer'  [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/logclear'    [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/sense'        [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/sl2'          [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/sshdu'        [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/s'            [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/sl2new.c'    [ Not found ]
[05:46:37]  Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[05:46:37]  Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[05:46:37]  Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[05:46:37]  Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[05:46:37]  Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[05:46:37]  Checking for file '/www/cgi-bin/becys.cgi'      [ Not found ]
[05:46:37]  Checking for directory '/dev/ida/.inet'        [ Not found ]
[05:46:37] Xzibit Rootkit                                    [ Not found ]
[05:46:37]
[05:46:37] Checking for zaRwT.KiT Rootkit...
[05:46:37]  Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[05:46:37]  Checking for file '/dev/ttyf'                  [ Not found ]
[05:46:37]  Checking for file '/dev/ttyp'                  [ Not found ]
[05:46:37]  Checking for file '/dev/ttyn'                  [ Not found ]
[05:46:37]  Checking for file '/rk/tulz'                    [ Not found ]
[05:46:37]  Checking for directory '/rk'                    [ Not found ]
[05:46:37]  Checking for directory '/dev/rd/s'              [ Not found ]
[05:46:37] zaRwT.KiT Rootkit                                [ Not found ]
[05:46:37]
[05:46:37] Checking for ZK Rootkit...
[05:46:37]  Checking for file '/usr/share/.zk/zk'          [ Not found ]
[05:46:37]  Checking for file '/usr/X11R6/.zk/xfs'          [ Not found ]
[05:46:37]  Checking for file '/usr/X11R6/.zk/echo'        [ Not found ]
[05:46:37]  Checking for file '/etc/1ssue.net'              [ Not found ]
[05:46:37]  Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[05:46:37]  Checking for directory '/usr/share/.zk'        [ Not found ]
[05:46:37]  Checking for directory '/usr/X11R6/.zk'        [ Not found ]
[05:46:37] ZK Rootkit                                        [ Not found ]
[05:47:55]
[05:47:55] Info: Starting test name 'additional_rkts'
[05:47:55] Performing additional rootkit checks
[05:47:55]
[05:47:55]  Performing Suckit Rookit additional checks
[05:47:55]    Checking hard link count on '/sbin/init'      [ OK ]
[05:47:55]    Checking for hidden file extensions          [ None found ]
[05:47:55]    Running skdet command                        [ Skipped ]
[05:47:55] Info: Unable to find the 'skdet' command
[05:47:55]  Suckit Rookit additional checks                [ OK ]
[05:47:55]
[05:47:55] Info: Starting test name 'possible_rkt_files'
[05:47:55]  Performing check of possible rootkit files and directories
[05:47:55]    Checking for file '/dev/sdr0'                [ Not found ]
[05:47:55]    Checking for file '/dev/pisu'                [ Not found ]
[05:47:55]    Checking for file '/dev/xdta'                [ Not found ]
[05:47:55]    Checking for file '/dev/saux'                [ Not found ]
[05:47:55]    Checking for file '/dev/hdx'                  [ Not found ]
[05:47:55]    Checking for file '/dev/hdx1'                [ Not found ]
[05:47:55]    Checking for file '/dev/hdx2'                [ Not found ]
[05:47:55]    Checking for file '/dev/ptyy'                [ Not found ]
[05:47:55]    Checking for file '/dev/ptyu'                [ Not found ]
[05:47:55]    Checking for file '/dev/ptyv'                [ Not found ]
[05:47:55]    Checking for file '/dev/hdbb'                [ Not found ]
[05:47:55]    Checking for file '/tmp/.syshackfile'        [ Not found ]
[05:47:55]    Checking for file '/tmp/.bash_history'        [ Not found ]
[05:47:55]    Checking for file '/usr/info/.clib'          [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/tcp.log'        [ Not found ]
[05:47:55]    Checking for file '/usr/bin/take/pid'        [ Not found ]
[05:47:55]    Checking for file '/sbin/create'              [ Not found ]
[05:47:55]    Checking for file '/dev/ttypz'                [ Not found ]
[05:47:55]    Checking for file '/var/log/tcp.log'          [ Not found ]
[05:47:55]    Checking for file '/usr/include/audit.h'      [ Not found ]
[05:47:55]    Checking for file '/usr/bin/sourcemask'      [ Not found ]
[05:47:55]    Checking for file '/usr/bin/ras2xm'          [ Not found ]
[05:47:55]    Checking for file '/dev/xmx'                  [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/gpm.root'        [ Not found ]
[05:47:55]    Checking for file '/bin/vobiscum'            [ Not found ]
[05:47:55]    Checking for file '/bin/psr'                  [ Not found ]
[05:47:55]    Checking for file '/dev/kdx'                  [ Not found ]
[05:47:55]    Checking for file '/dev/dkx'                  [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/sshd3'          [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/jcd'            [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/atd2'            [ Not found ]
[05:47:55]    Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[05:47:55]    Checking for file '/home/httpd/cgi-bin/psid'  [ Not found ]
[05:47:55]    Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/init.d/system'  [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/rc3.d/S93users'  [ Not found ]
[05:47:55]    Checking for file '/tmp/.ush'                [ Not found ]
[05:47:55]    Checking for file '/usr/lib/libhidefile.so'  [ Not found ]
[05:47:55]    Checking for file '/etc/cron.d/kmod'          [ Not found ]
[05:47:55]    Checking for file '/usr/lib/dmis/dmisd'      [ Not found ]
[05:47:55]    Checking for file '/lib/secure/libhij.so'    [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/sshd3'          [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/init.d/crontab'  [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/atd2'            [ Not found ]
[05:47:55]    Checking for file '/etc/rc.d/rc5.d/S93users'  [ Not found ]
[05:47:55]    Checking for file '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:47:55]    Checking for file '/etc/init.d/xfs3'          [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/t.txt'          [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/change'          [ Not found ]
[05:47:55]    Checking for file '/usr/sbin/s'              [ Not found ]
[05:47:55]    Checking for file '/bin/f'                    [ Not found ]
[05:47:55]    Checking for file '/bin/i'                    [ Not found ]
[05:47:55]    Checking for file '/lib/libncom.so.4.0.1'    [ Not found ]
[05:47:55]    Checking for file '/sbin/zinit'              [ Not found ]
[05:47:55]    Checking for file '/tmp/pass_ssh.log'        [ Not found ]
[05:47:56]    Checking for file '/usr/include/gpm2.h'      [ Not found ]
[05:47:56]    Checking for file '/etc/ssh/.sshd_auth'      [ Not found ]
[05:47:56]    Checking for file '/usr/lib/.sshd.h'          [ Not found ]
[05:47:56]    Checking for file '/var/run/.defunct'        [ Not found ]
[05:47:56]    Checking for file '/etc/httpd/run/.defunct'  [ Not found ]
[05:47:56]    Checking for file '/usr/share/pci.r'          [ Not found ]
[05:47:56]    Checking for file '/etc/cron.daily/dnsquery'  [ Not found ]
[05:47:56]    Checking for file '/usr/lib/libutil1.2.1.2.so' [ Not found ]
[05:47:56]    Checking for file '/bin/ceva'                [ Not found ]
[05:47:56]    Checking for file '/sbin/syslogd<SP>'        [ Not found ]
[05:47:56]    Checking for file '/usr/include/shup.h'      [ Not found ]
[05:47:56]    Checking for file '/etc/rpm/sshdOLD'          [ Not found ]
[05:47:56]    Checking for file '/etc/rpm/sshOLD'          [ Not found ]
[05:47:56]    Checking for file '/usr/share/passwd.h'      [ Not found ]
[05:47:56]    Checking for file '/lib/.xsyslog'            [ Not found ]
[05:47:56]    Checking for file '/etc/.xsyslog'            [ Not found ]
[05:47:56]    Checking for file '/lib/.ssyslog'            [ Not found ]
[05:47:56]    Checking for file '/tmp/.sendmail'            [ Not found ]
[05:47:56]    Checking for file '/usr/share/sshd.sync'      [ Not found ]
[05:47:56]    Checking for file '/bin/zcut'                [ Not found ]
[05:47:56]    Checking for file '/usr/bin/zmuie'            [ Not found ]
[05:47:56]    Checking for file '/lib/libkeyutils.so.1.9'  [ Not found ]
[05:47:56]    Checking for file '/lib64/libkeyutils.so.1.9' [ Not found ]
[05:47:56]    Checking for file '/usr/lib/libkeyutils.so.1.9' [ Not found ]
[05:47:56]    Checking for file '/usr/lib64/libkeyutils.so.1.9' [ Not found ]
[05:47:56]    Checking for directory '/dev/ptyas'          [ Not found ]
[05:47:56]    Checking for directory '/usr/bin/take'        [ Not found ]
[05:47:56]    Checking for directory '/usr/src/.lib'        [ Not found ]
[05:47:56]    Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[05:47:56]    Checking for directory '/lib/lblip.tk'        [ Not found ]
[05:47:56]    Checking for directory '/usr/sbin/...'        [ Not found ]
[05:47:56]    Checking for directory '/usr/share/.gun'      [ Not found ]
[05:47:56]    Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[05:47:56]    Checking for directory '/usr/man/man1/..<SP><SP>/.dir' [ Not found ]
[05:47:56]    Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[05:47:56]    Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[05:47:56]    Checking for directory '/tmp/.sys'            [ Not found ]
[05:47:56]    Checking for directory '/tmp/''              [ Not found ]
[05:47:56]    Checking for directory '/tmp/.,'              [ Not found ]
[05:47:56]    Checking for directory '/tmp/,.,'            [ Not found ]
[05:47:56]    Checking for directory '/dev/shm/emilien'    [ Not found ]
[05:47:56]    Checking for directory '/var/tmp/.log'        [ Not found ]
[05:47:56]    Checking for directory '/tmp/zmeu/...<SP>'    [ Not found ]
[05:47:56]    Checking for directory '/var/log/ssh'        [ Not found ]
[05:47:56]    Checking for directory '/dev/ida'            [ Not found ]
[05:47:56]    Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[05:47:56]    Checking for directory '/usr/lib/libshtift'  [ Not found ]
[05:47:56]    Checking for directory '/usr/src/.poop'      [ Not found ]
[05:47:56]    Checking for directory '/dev/wd4'            [ Not found ]
[05:47:56]    Checking for directory '/var/run/.tmp'        [ Not found ]
[05:47:56]    Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[05:47:56]    Checking for directory '/dev/portd'          [ Not found ]
[05:47:56]    Checking for directory '/dev/...'            [ Not found ]
[05:47:56]    Checking for directory '/usr/share/man/mansps' [ Not found ]
[05:47:56]    Checking for directory '/lib/.so'            [ Not found ]
[05:47:56]    Checking for directory '/lib/.sso'            [ Not found ]
[05:47:56]    Checking for directory '/usr/include/sslv3'  [ Not found ]
[05:47:56]    Checking for directory '/dev/shm/sshd'        [ Not found ]
[05:47:56]    Checking for directory '/usr/share/locale/mk/.dev/sk' [ Not found ]
[05:47:56]    Checking for directory '/usr/share/locale/mk/.dev' [ Not found ]
[05:47:56]    Checking for directory '/usr/include/netda.h' [ Not found ]
[05:47:56]    Checking for directory '/usr/include/.ssh'    [ Not found ]
[05:47:57]    Checking for directory '/usr/share/locale/jp/.<SP>' [ Not found ]
[05:47:57]    Checking for directory '/usr/share/.sqe'      [ Not found ]
[05:47:57]  Checking for possible rootkit files and directories [ None found ]
[05:47:57]
[05:47:57] Info: Starting test name 'possible_rkt_strings'
[05:47:57]  Performing check for possible rootkit strings
[05:47:57] Info: Using system startup paths: /etc/rc.local /etc/init.d
[05:47:57]    Checking for string 'phalanx'                [ Not found ]
[05:47:57]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[05:47:57]    Checking for string 'FUCK'                    [ Not found ]
[05:47:57]    Checking for string 'backdoor'                [ Not found ]
[05:47:57]    Checking for string '/usr/bin/rcpc'          [ Not found ]
[05:47:57]    Checking for string '/usr/sbin/login'        [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[05:47:57]    Checking for string 'vt200'                  [ Not found ]
[05:47:57]    Checking for string '/usr/bin/xstat'          [ Not found ]
[05:47:57]    Checking for string '/bin/envpc'              [ Not found ]
[05:47:57]    Checking for string 'L4m3r0x'                [ Not found ]
[05:47:57]    Checking for string '/lib/libext'            [ Not found ]
[05:47:57]    Checking for string '/usr/sbin/login'        [ Not found ]
[05:47:57]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[05:47:57]    Checking for string 'sendmail'                [ Not found ]
[05:47:57]    Checking for string 'cocacola'                [ Not found ]
[05:47:57]    Checking for string 'joao'                    [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[05:47:57]    Checking for string '/dev/sgk'                [ Not found ]
[05:47:57]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[05:47:57]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[05:47:57]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[05:47:57]    Checking for string '/lib/.sso'              [ Not found ]
[05:47:57]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[05:47:57]    Checking for string '/dev/caca'              [ Not found ]
[05:47:57]    Checking for string '/dev/ttyoa'              [ Not found ]
[05:47:57]    Checking for string '/usr/lib/ldlibns.so'    [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.addr'        [ Not found ]
[05:47:57]    Checking for string 'syg'                    [ Not found ]
[05:47:57]    Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[05:47:57]    Checking for string '/dev/pts/01'            [ Not found ]
[05:47:57]    Checking for string 'tw33dl3'                [ Not found ]
[05:47:57]    Checking for string 'psniff'                  [ Not found ]
[05:47:57]    Checking for string 'uconf.inv'              [ Not found ]
[05:47:57]    Checking for string 'lib/ldlibps.so'          [ Not found ]
[05:47:57]    Checking for string '/usr/lib/ldlibpst.so'    [ Not found ]
[05:47:57]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[05:47:57]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[05:47:57]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:47:57]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:47:57]    Checking for string '/bin/bash'              [ Not found ]
[05:47:57]    Checking for string '/dev/xdta'              [ Not found ]
[05:47:57]    Checking for string '/usr/lib/.tbd'          [ Not found ]
[05:47:58]    Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[05:47:58]    Checking for string 'in.inetd'                [ Not found ]
[05:47:58]    Checking for string '#<HIDE_.*>'              [ Not found ]
[05:47:58]    Checking for string 'bin/xchk'                [ Not found ]
[05:47:59]    Checking for string 'bin/xsf'                [ Not found ]
[05:47:59]    Checking for string '/usr/bin/ssh2d'          [ Not found ]
[05:47:59]    Checking for string '/usr/sbin/xntps'        [ Not found ]
[05:47:59]    Checking for string 'ttyload'                [ Not found ]
[05:47:59]    Checking for string '/etc/rc.d/init.d/init'  [ Not found ]
[05:48:00]    Checking for string 'usr/bin/xfss'            [ Not found ]
[05:48:00]    Checking for string '/usr/sbin/rpc.netinet'  [ Not found ]
[05:48:00]    Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[05:48:00]    Checking for string '/usr/lib/.fx/xs'        [ Not found ]
[05:48:00]    Checking for string '/ssh2d'                  [ Not found ]
[05:48:01]    Checking for string '/dev/kmod'              [ Not found ]
[05:48:01]    Checking for string '/crth.o'                [ Not found ]
[05:48:01]    Checking for string '/crtz.o'                [ Not found ]
[05:48:01]    Checking for string '/dev/dos'                [ Not found ]
[05:48:01]    Checking for string '/lpq'                    [ Not found ]
[05:48:02]    Checking for string '/usr/sbin/rescue'        [ Not found ]
[05:48:02]    Checking for string '/usr/lib/lpstart'        [ Not found ]
[05:48:02]    Checking for string '/volc'                  [ Not found ]
[05:48:02]    Checking for string 'sourcemask'              [ Not found ]
[05:48:03]    Checking for string '/bin/vobiscum'          [ Not found ]
[05:48:03]    Checking for string '/usr/sbin/in.telnet'    [ Not found ]
[05:48:03]    Checking for string '/usr/bin/hdparm?-t1?-X53?-p' [ Not found ]
[05:48:03]    Checking for string '/lib/.xsyslog'          [ Not found ]
[05:48:03]    Checking for string '/etc/.xsyslog'          [ Not found ]
[05:48:04]    Checking for string '/lib/.ssyslog'          [ Not found ]
[05:48:04]    Checking for string '/tmp/.sendmail'          [ Not found ]
[05:48:04]    Checking for string '/lib/ldd.so/tkps'        [ Not found ]
[05:48:04]    Checking for string 't0rnkit'                [ Not found ]
[05:48:04]    Checking for string '/dev/proc/fuckit'        [ Not found ]
[05:48:04]    Checking for string 'backdoor.h'              [ Not found ]
[05:48:04]    Checking for string 'backdoor_active'        [ Not found ]
[05:48:04]    Checking for string 'magic_pass_active'      [ Not found ]
[05:48:04]    Checking for string '/usr/include/gpm2.h'    [ Not found ]
[05:48:04]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:48:04]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:48:04]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:48:04]    Checking for string '/usr/lib/ldlibct.so'    [ Not found ]
[05:48:04]    Checking for string '/usr/lib/ldlibdu.so'    [ Not found ]
[05:48:04]    Checking for string '/dev/ptyxx/.file'        [ Not found ]
[05:48:04]    Checking for string 'libproc.so.2.0.7'        [ Not found ]
[05:48:04]    Checking for string '/dev/ida/.inet'          [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:04]    Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[05:48:05]    Checking for string 'backconnect'            [ Not found ]
[05:48:05]    Checking for string 'magic?packet?received'  [ Not found ]
[05:48:05]  Checking for possible rootkit strings          [ None found ]
[05:48:05]
[05:48:05] Info: Starting test name 'malware'
[05:48:05] Performing malware checks
[05:48:05]
[05:48:05] Info: Test 'deleted_files' disabled at users request.
[05:48:05]
[05:48:05] Info: Starting test name 'running_procs'
[05:48:06]  Checking running processes for suspicious files [ None found ]
[05:48:06]
[05:48:06] Info: Test 'hidden_procs' disabled at users request.
[05:48:06]
[05:48:06] Info: Test 'suspscan' disabled at users request.
[05:48:06]
[05:48:06] Info: Starting test name 'other_malware'
[05:48:06]  Performing check for login backdoors
[05:48:06]    Checking for '/bin/.login'                    [ Not found ]
[05:48:06]    Checking for '/sbin/.login'                  [ Not found ]
[05:48:06]  Checking for login backdoors                    [ None found ]
[05:48:06]
[05:48:06]  Performing check for suspicious directories
[05:48:06]    Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[05:48:06]    Checking for directory '/dev/rd/cdb'          [ Not found ]
[05:48:06]  Checking for suspicious directories            [ None found ]
[05:48:06]
[05:48:06]  Checking for software intrusions                [ Skipped ]
[05:48:06] Info: Check skipped - tripwire not installed
[05:48:06]
[05:48:06]  Performing check for sniffer log files
[05:48:06]    Checking for file '/usr/lib/libice.log'      [ Not found ]
[05:48:06]    Checking for file '/dev/prom/sn.l'            [ Not found ]
[05:48:06]    Checking for file '/dev/fd/.88/zxsniff.log'  [ Not found ]
[05:48:06]  Checking for sniffer log files                  [ None found ]
[05:48:06]
[05:48:06] Suspicious Shared Memory segments
[05:48:06]  Suspicious Shared Memory segments              [ None found ]
[05:48:06]
[05:48:06] Info: Starting test name 'trojans'
[05:48:06] Performing trojan specific checks
[05:48:06]  Checking for enabled inetd services            [ Skipped ]
[05:48:06] Info: Check skipped - file '/etc/inetd.conf' does not exist.
[05:48:06]
[05:48:06]  Performing check for enabled xinetd services
[05:48:06]  Checking for enabled xinetd services            [ Skipped ]
[05:48:06] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[05:48:06]  Checking for Apache backdoor                    [ Not found ]
[05:48:06]
[05:48:06] Info: Starting test name 'os_specific'
[05:48:06] Performing Linux specific checks
[05:48:07]  Checking loaded kernel modules                  [ OK ]
[05:48:07] Info: Using modules pathname of '/lib/modules/4.2.0-35-generic'
[05:48:09]  Checking kernel module names                    [ OK ]
[05:48:11]
[05:48:11] Info: Starting test name 'network'
[05:48:11] Checking the network...
[05:48:11]
[05:48:11] Performing checks on the network ports
[05:48:11] Info: Starting test name 'ports'
[05:48:11]  Performing check for backdoor ports
[05:48:11]    Checking for TCP port 1524                    [ Not found ]
[05:48:11]    Checking for TCP port 1984                    [ Not found ]
[05:48:11]    Checking for UDP port 2001                    [ Not found ]
[05:48:11]    Checking for TCP port 2006                    [ Not found ]
[05:48:11]    Checking for TCP port 2128                    [ Not found ]
[05:48:11]    Checking for TCP port 6666                    [ Not found ]
[05:48:11]    Checking for TCP port 6667                    [ Not found ]
[05:48:11]    Checking for TCP port 6668                    [ Not found ]
[05:48:11]    Checking for TCP port 6669                    [ Not found ]
[05:48:11]    Checking for TCP port 7000                    [ Not found ]
[05:48:11]    Checking for TCP port 13000                  [ Not found ]
[05:48:11]    Checking for TCP port 14856                  [ Not found ]
[05:48:11]    Checking for TCP port 25000                  [ Not found ]
[05:48:11]    Checking for TCP port 29812                  [ Not found ]
[05:48:11]    Checking for TCP port 31337                  [ Not found ]
[05:48:11]    Checking for TCP port 32982                  [ Not found ]
[05:48:11]    Checking for TCP port 33369                  [ Not found ]
[05:48:11]    Checking for TCP port 47107                  [ Not found ]
[05:48:11]    Checking for TCP port 47018                  [ Not found ]
[05:48:11]    Checking for TCP port 60922                  [ Not found ]
[05:48:12]    Checking for TCP port 62883                  [ Not found ]
[05:48:12]    Checking for TCP port 65535                  [ Not found ]
[05:48:12]  Checking for backdoor ports                    [ None found ]
[05:48:12]
[05:48:12] Info: Starting test name 'hidden_ports'
[05:48:12] Info: Found the 'unhide-tcp' command: /usr/sbin/unhide-tcp
[05:48:12]  Checking for hidden ports                      [ None found ]
[05:48:12]
[05:48:12] Performing checks on the network interfaces
[05:48:12] Info: Starting test name 'promisc'
[05:48:12]  Checking for promiscuous interfaces            [ None found ]
[05:48:12]
[05:48:12] Info: Test 'packet_cap_apps' disabled at users request.
[05:48:12]
[05:48:12] Info: Starting test name 'local_host'
[05:48:12] Checking the local host...
[05:48:12]
[05:48:12] Info: Starting test name 'startup_files'
[05:48:12] Performing system boot checks
[05:48:12]  Checking for local host name                    [ Found ]
[05:48:12]
[05:48:12] Info: Starting test name 'startup_malware'
[05:48:12]  Checking for system startup files              [ Found ]
[05:48:13]  Checking system startup files for malware      [ None found ]
[05:48:13]
[05:48:13] Info: Starting test name 'group_accounts'
[05:48:13] Performing group and account checks
[05:48:13]  Checking for passwd file                        [ Found ]
[05:48:13] Info: Found password file: /etc/passwd
[05:48:13]  Checking for root equivalent (UID 0) accounts  [ None found ]
[05:48:13] Info: Found shadow file: /etc/shadow
[05:48:13]  Checking for passwordless accounts              [ None found ]
[05:48:13]
[05:48:13] Info: Starting test name 'passwd_changes'
[05:48:13]  Checking for passwd file changes                [ Warning ]
[05:48:13] Warning: User 'havp' has been added to the passwd file.
[05:48:13] Warning: User 'clamav' has been added to the passwd file.
[05:48:13] Warning: User 'clamsmtp' has been added to the passwd file.
[05:48:13] Warning: User 'amavis' has been added to the passwd file.
[05:48:13] Warning: User 'clickpkg' has been added to the passwd file.
[05:48:13] Warning: User 'dirmngr' has been added to the passwd file.
[05:48:13]
[05:48:13] Info: Starting test name 'group_changes'
[05:48:13]  Checking for group file changes                [ Warning ]
[05:48:13] Warning: Group 'vboxusers' has been added to the group file.
[05:48:13] Warning: Group 'havp' has been added to the group file.
[05:48:13] Warning: Group 'clamav' has been added to the group file.
[05:48:13] Warning: Group 'clamsmtp' has been added to the group file.
[05:48:13] Warning: Group 'amavis' has been added to the group file.
[05:48:13] Warning: Group 'autopilot' has been added to the group file.
[05:48:13] Warning: Group 'clickpkg' has been added to the group file.
[05:48:13] Warning: Group 'dirmngr' has been added to the group file.
[05:48:13]  Checking root account shell history files      [ None found ]
[05:48:13]
[05:48:13] Info: Starting test name 'system_configs'
[05:48:13] Performing system configuration file checks
[05:48:13]  Checking for an SSH configuration file          [ Not found ]
[05:48:14]  Checking for a running system logging daemon    [ Found ]
[05:48:14] Info: A running 'rsyslog' daemon has been found.
[05:48:14] Info: A running 'systemd-journald' daemon has been found.
[05:48:14] Info: Found an rsyslog configuration file: /etc/rsyslog.conf
[05:48:14] Info: Found a systemd configuration file: /etc/systemd/journald.conf
[05:48:14]  Checking for a system logging configuration file [ Found ]
[05:48:14]  Checking if syslog remote logging is allowed    [ Not allowed ]
[05:48:14]
[05:48:14] Info: Starting test name 'filesystem'
[05:48:14] Performing filesystem checks
[05:48:14] Info: SCAN_MODE_DEV set to 'THOROUGH'
[05:48:15]  Checking /dev for suspicious file types        [ Warning ]
[05:48:15] Warning: Suspicious file types found in /dev:
[05:48:15]          /dev/shm/pulse-shm-4209799112: data
[05:48:15]          /dev/shm/pulse-shm-2804304956: data
[05:48:15]          /dev/shm/pulse-shm-314701331: data
[05:48:15]          /dev/shm/pulse-shm-2251038954: data
[05:48:15]          /dev/shm/pulse-shm-1056751454: data
[05:48:15]          /dev/shm/pulse-shm-4207284760: data
[05:48:15]          /dev/shm/pulse-shm-4133351312: data
[05:48:15]          /dev/shm/ecryptfs-bbs-Private: ASCII text
[05:48:15]          /dev/shm/pulse-shm-1962024324: data
[05:48:15]          /dev/shm/pulse-shm-995775837: data
[05:48:15]  Checking for hidden files and directories      [ Warning ]
[05:48:15] Warning: Hidden file found: /etc/.oinkmaster.conf.swp: data
[05:48:15]  Checking for missing log files                  [ Skipped ]
[05:48:15]  Checking for empty log files                    [ Skipped ]
[05:48:20]
[05:48:20] Info: Test 'apps' disabled at users request.
[05:48:21]
[05:48:21] System checks summary
[05:48:21] =====================
[05:48:21]
[05:48:21] File properties checks...
[05:48:21] Files checked: 147
[05:48:21] Suspect files: 147
[05:48:21]
[05:48:21] Rootkit checks...
[05:48:21] Rootkits checked : 365
[05:48:21] Possible rootkits: 0
[05:48:21]
[05:48:21] Applications checks...
[05:48:21] All checks skipped
[05:48:21]
[05:48:21] The system checks took: 2 minutes and 19 seconds
[05:48:21]
[05:48:21] Info: End date is Sa 16. Apr 05:48:21 CEST 2016


dennisstein 16.04.2016 04:39

Authlog Teil 1

Code:

Apr 14 20:53:00 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22342:284322 (system bus name :1.225 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:00 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22342:284322 (system bus name :1.225, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22355:284357 (system bus name :1.227 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22355:284357 (system bus name :1.227, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22378:284392 (system bus name :1.228 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22378:284392 (system bus name :1.228, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22395:284403 (system bus name :1.229 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:01 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22395:284403 (system bus name :1.229, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22511:284870 (system bus name :1.230 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22511:284870 (system bus name :1.230, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22548:284889 (system bus name :1.231 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22548:284889 (system bus name :1.231, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22568:284905 (system bus name :1.232 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:53:06 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22568:284905 (system bus name :1.232, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 14 20:56:19 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 14 20:56:19 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 14 20:56:19 bbs-sophos pkexec[24529]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Apr 14 21:12:54 bbs-sophos systemd-logind[785]: System is rebooting.
Apr 15 02:04:15 bbs-sophos systemd-logind[766]: New seat seat0.
Apr 15 02:04:15 bbs-sophos systemd-logind[766]: Watching system buttons on /dev/input/event2 (Power Button)
Apr 15 02:04:15 bbs-sophos systemd-logind[766]: Watching system buttons on /dev/input/event3 (Video Bus)
Apr 15 02:04:15 bbs-sophos systemd-logind[766]: Watching system buttons on /dev/input/event0 (Power Button)
Apr 15 02:04:15 bbs-sophos systemd-logind[766]: Watching system buttons on /dev/input/event1 (Sleep Button)
Apr 15 02:04:27 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 02:04:27 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 02:04:27 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 02:04:27 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 02:04:27 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Apr 15 02:04:27 bbs-sophos systemd-logind[766]: New session c1 of user lightdm.
Apr 15 02:04:27 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Apr 15 02:04:33 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 02:04:33 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 02:04:33 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 02:04:33 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 02:04:33 bbs-sophos lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "bbs"
Apr 15 02:04:51 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Apr 15 02:04:51 bbs-sophos lightdm: pam_unix(lightdm:session): session opened for user bbs by (uid=0)
Apr 15 02:04:51 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user bbs by (uid=0)
Apr 15 02:04:51 bbs-sophos systemd-logind[766]: New session c2 of user bbs.
Apr 15 02:04:59 bbs-sophos dbus[767]: [system] Failed to activate service 'org.bluez': timed out
Apr 15 02:05:00 bbs-sophos gnome-keyring-daemon[1118]: The PKCS#11 component was already initialized
Apr 15 02:05:00 bbs-sophos gnome-keyring-daemon[1118]: The Secret Service was already initialized
Apr 15 02:05:01 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.72 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:06:27 bbs-sophos systemd-logind[766]: Removed session c1.
Apr 15 02:06:27 bbs-sophos systemd: pam_unix(systemd-user:session): session closed for user lightdm
Apr 15 02:17:01 bbs-sophos CRON[2290]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 02:17:01 bbs-sophos CRON[2290]: pam_unix(cron:session): session closed for user root
Apr 15 02:25:12 bbs-sophos dbus[767]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.103" (uid=0 pid=2365 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.12" (uid=0 pid=783 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 15 02:26:19 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install tiger
Apr 15 02:26:19 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:27:42 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:3784:145618 (system bus name :1.106 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:42 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:3784:145618 (system bus name :1.106, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:49 bbs-sophos groupadd[3857]: group added to /etc/group: name=smmta, GID=129
Apr 15 02:27:49 bbs-sophos groupadd[3857]: group added to /etc/gshadow: name=smmta
Apr 15 02:27:50 bbs-sophos groupadd[3857]: new group: name=smmta, GID=129
Apr 15 02:27:50 bbs-sophos useradd[3863]: new user: name=smmta, UID=120, GID=129, home=/var/lib/sendmail, shell=/bin/false
Apr 15 02:27:50 bbs-sophos usermod[3879]: change user 'smmta' password
Apr 15 02:27:50 bbs-sophos chage[3886]: changed password expiry for smmta
Apr 15 02:27:50 bbs-sophos chfn[3889]: changed user 'smmta' information
Apr 15 02:27:51 bbs-sophos groupadd[3909]: group added to /etc/group: name=smmsp, GID=130
Apr 15 02:27:51 bbs-sophos groupadd[3909]: group added to /etc/gshadow: name=smmsp
Apr 15 02:27:51 bbs-sophos groupadd[3909]: new group: name=smmsp, GID=130
Apr 15 02:27:51 bbs-sophos useradd[3919]: new user: name=smmsp, UID=121, GID=130, home=/var/lib/sendmail, shell=/bin/false
Apr 15 02:27:51 bbs-sophos usermod[3927]: change user 'smmsp' password
Apr 15 02:27:51 bbs-sophos chage[3934]: changed password expiry for smmsp
Apr 15 02:27:51 bbs-sophos chfn[3975]: changed user 'smmsp' information
Apr 15 02:27:53 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:4105:146727 (system bus name :1.107 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:53 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:4105:146727 (system bus name :1.107, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:53 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:4147:146745 (system bus name :1.108 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:54 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:4147:146745 (system bus name :1.108, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:54 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:4195:146798 (system bus name :1.109 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:54 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:4195:146798 (system bus name :1.109, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:54 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:4214:146810 (system bus name :1.110 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:54 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:4214:146810 (system bus name :1.110, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:57 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:5008:147057 (system bus name :1.111 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:57 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:5008:147057 (system bus name :1.111, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:27:57 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:5068:147074 (system bus name :1.112 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:27:59 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:5068:147074 (system bus name :1.112, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:28:55 bbs-sophos polkit-agent-helper-1[11903]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 02:28:55 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.84 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 02:29:02 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:12018:153632 (system bus name :1.114 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:29:02 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:12018:153632 (system bus name :1.114, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:29:04 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:29:22 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/tiger
Apr 15 02:29:22 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:30:00 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install chkrootkit
Apr 15 02:30:00 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:30:00 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:30:42 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.apport.apport-gtk-root for unix-process:1125:8533 [/sbin/upstart --user] (owned by unix-user:bbs)
Apr 15 02:30:42 bbs-sophos pkexec[30463]: bbs: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/share/apport/apport-gtk]
Apr 15 02:31:09 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:32:23 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install gksu
Apr 15 02:32:23 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:32:23 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:33:37 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install gksu
Apr 15 02:33:37 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:33:37 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:37:00 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:21024:201360 (system bus name :1.120 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:37:00 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:21024:201360 (system bus name :1.120, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:38:56 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:21570:213007 (system bus name :1.122 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:38:56 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:21570:213007 (system bus name :1.122, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:38:56 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:21607:213042 (system bus name :1.123 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:38:57 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:21607:213042 (system bus name :1.123, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:38:57 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:21630:213053 (system bus name :1.124 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:38:58 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:21630:213053 (system bus name :1.124, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:40:01 bbs-sophos CRON[22238]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 02:40:01 bbs-sophos CRON[22238]: pam_unix(cron:session): session closed for user smmsp
Apr 15 02:40:11 bbs-sophos su[22440]: Successful su for www-data by root
Apr 15 02:40:11 bbs-sophos su[22440]: + ??? root:www-data
Apr 15 02:40:11 bbs-sophos su[22440]: pam_unix(su:session): session opened for user www-data by (uid=0)
Apr 15 02:40:11 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user www-data by (uid=0)
Apr 15 02:40:11 bbs-sophos systemd-logind[766]: New session c3 of user www-data.
Apr 15 02:40:11 bbs-sophos su[22440]: pam_unix(su:session): session closed for user www-data
Apr 15 02:40:11 bbs-sophos systemd-logind[766]: Removed session c3.
Apr 15 02:40:21 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22745:221480 (system bus name :1.135 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 02:40:21 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22745:221480 (system bus name :1.135, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 02:41:41 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install gksu
Apr 15 02:41:41 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:41:42 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:42:00 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get autoremove
Apr 15 02:42:00 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:42:07 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:42:20 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install gksu
Apr 15 02:42:20 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:42:20 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:42:42 bbs-sophos sudo:      bbs : TTY=unknown ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/geany /var/log/tiger/security.report.bbs-sophos.160415-02:29
Apr 15 02:42:42 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Apr 15 02:44:29 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install chkrootkit
Apr 15 02:44:29 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:44:29 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:44:53 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/chkrootkit --update
Apr 15 02:44:53 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:44:53 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:45:22 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/chkrootkit -V
Apr 15 02:45:22 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:45:22 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:46:10 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/chkrootkit -r
Apr 15 02:46:10 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:46:10 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:46:18 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/chkrootkit
Apr 15 02:46:18 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:46:20 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:51:17 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:54:04 bbs-sophos sudo:      bbs : TTY=unknown ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/geany /var/log/tiger/security.report.bbs-sophos.160415-02:29
Apr 15 02:54:04 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Apr 15 02:54:29 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install rkhunter
Apr 15 02:54:29 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:54:59 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 02:55:11 bbs-sophos sudo:      bbs : TTY=pts/5 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter -c
Apr 15 02:55:11 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 02:55:12 bbs-sophos Rootkit Hunter: Rootkit hunter check started (version 1.4.2)
Apr 15 02:55:52 bbs-sophos Rootkit Hunter: Scanning took 40 seconds
Apr 15 02:55:52 bbs-sophos Rootkit Hunter: Please inspect this machine, because it may be infected.
Apr 15 02:55:52 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:00:01 bbs-sophos CRON[29922]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 03:00:01 bbs-sophos CRON[29923]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 03:00:01 bbs-sophos CRON[29922]: pam_unix(cron:session): session closed for user smmsp
Apr 15 03:00:02 bbs-sophos CRON[29923]: pam_unix(cron:session): session closed for user root
Apr 15 03:01:21 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --check
Apr 15 03:01:21 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:01:22 bbs-sophos Rootkit Hunter: Rootkit hunter check started (version 1.4.2)
Apr 15 03:02:02 bbs-sophos Rootkit Hunter: Scanning took 40 seconds
Apr 15 03:02:02 bbs-sophos Rootkit Hunter: Please inspect this machine, because it may be infected.
Apr 15 03:02:02 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:02:14 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --update
Apr 15 03:02:14 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:02:16 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:02:37 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --versioncheck
Apr 15 03:02:37 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:02:38 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:03:03 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --config-check
Apr 15 03:03:03 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:03:04 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:07:49 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --propupd / --hash {SHA1
Apr 15 03:07:49 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:07:49 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:08:07 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --propupd / --hash {SHA1}
Apr 15 03:08:07 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:08:07 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:08:15 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --propupd / --hash SHA1
Apr 15 03:08:15 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:08:18 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:09:56 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --hash SHA1 --vl
Apr 15 03:09:56 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:09:57 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:12:11 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/rkhunter --enable all --vl
Apr 15 03:12:11 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:12:12 bbs-sophos Rootkit Hunter: Rootkit hunter check started (version 1.4.2)
Apr 15 03:12:54 bbs-sophos Rootkit Hunter: Scanning took 41 seconds
Apr 15 03:12:54 bbs-sophos Rootkit Hunter: Please inspect this machine, because it may be infected.
Apr 15 03:12:54 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:16:06 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install lynis
Apr 15 03:16:06 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:16:12 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:16:30 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/lynis
Apr 15 03:16:30 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:16:30 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:17:01 bbs-sophos CRON[29663]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 03:17:01 bbs-sophos CRON[29663]: pam_unix(cron:session): session closed for user root
Apr 15 03:17:53 bbs-sophos sudo:      bbs : TTY=pts/19 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/lynis audit system
Apr 15 03:17:53 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 15 03:20:01 bbs-sophos CRON[28945]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 03:20:01 bbs-sophos CRON[28945]: pam_unix(cron:session): session closed for user smmsp
Apr 15 03:20:21 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:24:50 bbs-sophos polkit-agent-helper-1[30829]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 03:24:50 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.137 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 03:30:34 bbs-sophos polkit-agent-helper-1[31196]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 03:30:34 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.change-repository for system-bus-name::1.137 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 03:40:01 bbs-sophos CRON[31324]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 03:40:02 bbs-sophos CRON[31324]: pam_unix(cron:session): session closed for user smmsp
Apr 15 03:41:27 bbs-sophos polkit-agent-helper-1[31408]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 03:41:27 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.137 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 03:41:55 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action com.ubuntu.pkexec.synaptic for unix-process:31416:590511 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:bbs)
Apr 15 03:41:55 bbs-sophos pkexec[31419]: bbs: Error executing command as another user: Request dismissed [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/sbin/synaptic]
Apr 15 03:42:10 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:32336:592386 (system bus name :1.156 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:42:11 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:32336:592386 (system bus name :1.156, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:43:39 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 15 03:44:53 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:2486:608728 (system bus name :1.157 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:44:54 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:2486:608728 (system bus name :1.157, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:44:54 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:2503:608754 (system bus name :1.158 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:44:54 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:2503:608754 (system bus name :1.158, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:44:54 bbs-sophos groupadd[2525]: group added to /etc/group: name=vboxusers, GID=131
Apr 15 03:44:54 bbs-sophos groupadd[2525]: group added to /etc/gshadow: name=vboxusers
Apr 15 03:44:54 bbs-sophos groupadd[2525]: new group: name=vboxusers, GID=131
Apr 15 03:44:55 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:2666:608851 (system bus name :1.159 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:44:55 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:2666:608851 (system bus name :1.159, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:44:55 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:2691:608871 (system bus name :1.160 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:44:55 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:2691:608871 (system bus name :1.160, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:44:57 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:2735:609119 (system bus name :1.161 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 03:44:57 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:2735:609119 (system bus name :1.161, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 03:49:31 bbs-sophos polkit-agent-helper-1[3638]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 03:49:31 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.137 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 04:00:02 bbs-sophos CRON[4461]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 04:00:02 bbs-sophos CRON[4460]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 04:00:03 bbs-sophos CRON[4460]: pam_unix(cron:session): session closed for user smmsp
Apr 15 04:00:03 bbs-sophos CRON[4461]: pam_unix(cron:session): session closed for user root
Apr 15 04:08:35 bbs-sophos systemd-logind[766]: Power key pressed.
Apr 15 13:00:32 bbs-sophos systemd-logind[869]: New seat seat0.
Apr 15 13:00:32 bbs-sophos systemd-logind[869]: Watching system buttons on /dev/input/event2 (Power Button)
Apr 15 13:00:32 bbs-sophos systemd-logind[869]: Watching system buttons on /dev/input/event3 (Video Bus)
Apr 15 13:00:32 bbs-sophos systemd-logind[869]: Watching system buttons on /dev/input/event0 (Power Button)
Apr 15 13:00:32 bbs-sophos systemd-logind[869]: Watching system buttons on /dev/input/event1 (Sleep Button)
Apr 15 13:00:43 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 13:00:43 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 13:00:43 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 13:00:43 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 13:00:44 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Apr 15 13:00:44 bbs-sophos systemd-logind[869]: New session c1 of user lightdm.
Apr 15 13:00:44 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Apr 15 13:00:50 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 13:00:50 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 13:00:50 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 13:00:50 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 13:00:50 bbs-sophos lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "bbs"
Apr 15 13:01:16 bbs-sophos dbus[829]: [system] Failed to activate service 'org.bluez': timed out
Apr 15 13:01:26 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Apr 15 13:01:26 bbs-sophos lightdm: pam_unix(lightdm:session): session opened for user bbs by (uid=0)
Apr 15 13:01:26 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user bbs by (uid=0)
Apr 15 13:01:26 bbs-sophos systemd-logind[869]: New session c2 of user bbs.
Apr 15 13:01:29 bbs-sophos dbus[829]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.52" (uid=0 pid=1363 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.1" (uid=0 pid=817 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 15 13:01:38 bbs-sophos gnome-keyring-daemon[1339]: The PKCS#11 component was already initialized
Apr 15 13:01:38 bbs-sophos gnome-keyring-daemon[1339]: The Secret Service was already initialized
Apr 15 13:01:39 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.76 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 13:02:00 bbs-sophos dbus[829]: [system] Failed to activate service 'org.bluez': timed out
Apr 15 13:02:12 bbs-sophos polkit-agent-helper-1[2145]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 13:02:12 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain ONE-SHOT authorization for action com.ubuntu.apport.apport-gtk-root for unix-process:1346:11851 [/sbin/upstart --user] (owned by unix-user:bbs)
Apr 15 13:02:12 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 13:02:12 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 13:02:12 bbs-sophos pkexec[2135]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/share/apport/apport-gtk]
Apr 15 13:02:44 bbs-sophos systemd-logind[869]: Removed session c1.
Apr 15 13:02:44 bbs-sophos systemd: pam_unix(systemd-user:session): session closed for user lightdm
Apr 15 13:04:01 bbs-sophos sudo:    root : TTY=unknown ; PWD=/root ; USER=bbs ; ENV=DBUS_SESSION_BUS_ADDRESS=unix:abstract=/tmp/dbus-Lu3JvWNTAc,guid=c644bfa494c68dfe2b09f5125710ca0a ; COMMAND=/usr/bin/xdg-open https://bugs.launchpad.net/ubuntu/+source/dpkg/+filebug/98e9837a-02e0-11e6-9c18-002481e7f48a?field.title=package+liblockfile1%3Aamd64+1.09-6ubuntu1+failed+to+install%2Fupgrade%3A+package+liblockfile1%3Aamd64+is+already+installed+and+configured
Apr 15 13:04:01 bbs-sophos sudo: pam_unix(sudo:session): session opened for user bbs by (uid=0)
Apr 15 13:04:01 bbs-sophos sudo: pam_unix(sudo:session): session closed for user bbs
Apr 15 13:14:09 bbs-sophos sudo:    root : TTY=unknown ; PWD=/root ; USER=bbs ; ENV=DBUS_SESSION_BUS_ADDRESS=unix:abstract=/tmp/dbus-Lu3JvWNTAc,guid=c644bfa494c68dfe2b09f5125710ca0a ; COMMAND=/usr/bin/xdg-open https://bugs.launchpad.net/bugs/1384986
Apr 15 13:14:09 bbs-sophos sudo: pam_unix(sudo:session): session opened for user bbs by (uid=0)
Apr 15 13:14:12 bbs-sophos sudo: pam_unix(sudo:session): session closed for user bbs
Apr 15 13:15:04 bbs-sophos sudo:    root : TTY=unknown ; PWD=/root ; USER=bbs ; ENV=DBUS_SESSION_BUS_ADDRESS=unix:abstract=/tmp/dbus-Lu3JvWNTAc,guid=c644bfa494c68dfe2b09f5125710ca0a ; COMMAND=/usr/bin/xdg-open https://bugs.launchpad.net/ubuntu/+source/dpkg/+filebug/218c1f3e-02e2-11e6-911c-d485646cd9a4?field.title=package+liblockfile-bin+1.09-6ubuntu1+failed+to+install%2Fupgrade%3A+package+liblockfile-bin+is+already+installed+and+configured
Apr 15 13:15:04 bbs-sophos sudo: pam_unix(sudo:session): session opened for user bbs by (uid=0)
Apr 15 13:15:06 bbs-sophos sudo: pam_unix(sudo:session): session closed for user bbs
Apr 15 13:17:08 bbs-sophos CRON[3100]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 13:17:09 bbs-sophos CRON[3100]: pam_unix(cron:session): session closed for user root
Apr 15 13:20:04 bbs-sophos CRON[3106]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 13:20:20 bbs-sophos CRON[3106]: pam_unix(cron:session): session closed for user smmsp
Apr 15 13:40:03 bbs-sophos CRON[3247]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 13:40:09 bbs-sophos CRON[3247]: pam_unix(cron:session): session closed for user smmsp
Apr 15 14:00:04 bbs-sophos CRON[3308]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 14:00:05 bbs-sophos CRON[3307]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 14:00:10 bbs-sophos CRON[3307]: pam_unix(cron:session): session closed for user smmsp
Apr 15 14:00:22 bbs-sophos CRON[3308]: pam_unix(cron:session): session closed for user root
Apr 15 14:17:05 bbs-sophos CRON[3474]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 14:17:06 bbs-sophos CRON[3474]: pam_unix(cron:session): session closed for user root
Apr 15 14:20:01 bbs-sophos CRON[3479]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 14:20:06 bbs-sophos CRON[3479]: pam_unix(cron:session): session closed for user smmsp
Apr 15 14:40:03 bbs-sophos CRON[3531]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 14:40:08 bbs-sophos CRON[3531]: pam_unix(cron:session): session closed for user smmsp
Apr 15 15:00:05 bbs-sophos CRON[3655]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 15:00:07 bbs-sophos CRON[3654]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 15:00:13 bbs-sophos CRON[3654]: pam_unix(cron:session): session closed for user smmsp
Apr 15 15:00:20 bbs-sophos CRON[3655]: pam_unix(cron:session): session closed for user root
Apr 15 15:17:03 bbs-sophos CRON[3810]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 15:17:03 bbs-sophos CRON[3810]: pam_unix(cron:session): session closed for user root
Apr 15 15:20:03 bbs-sophos CRON[3816]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 15:20:10 bbs-sophos CRON[3816]: pam_unix(cron:session): session closed for user smmsp
Apr 15 15:40:03 bbs-sophos CRON[3860]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 15:40:05 bbs-sophos CRON[3860]: pam_unix(cron:session): session closed for user smmsp
Apr 15 15:57:14 bbs-sophos systemd-logind[883]: New seat seat0.
Apr 15 15:57:14 bbs-sophos systemd-logind[883]: Watching system buttons on /dev/input/event2 (Power Button)
Apr 15 15:57:14 bbs-sophos systemd-logind[883]: Watching system buttons on /dev/input/event3 (Video Bus)
Apr 15 15:57:14 bbs-sophos systemd-logind[883]: Watching system buttons on /dev/input/event0 (Power Button)
Apr 15 15:57:14 bbs-sophos systemd-logind[883]: Watching system buttons on /dev/input/event1 (Sleep Button)
Apr 15 15:57:22 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 15:57:22 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 15:57:22 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 15:57:22 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 15:57:22 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Apr 15 15:57:22 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Apr 15 15:57:22 bbs-sophos systemd-logind[883]: New session c1 of user lightdm.
Apr 15 15:57:27 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 15 15:57:27 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 15 15:57:27 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 15 15:57:27 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 15 15:57:27 bbs-sophos lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "bbs"
Apr 15 15:57:52 bbs-sophos dbus[851]: [system] Failed to activate service 'org.bluez': timed out
Apr 15 15:58:08 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Apr 15 15:58:08 bbs-sophos lightdm: pam_unix(lightdm:session): session opened for user bbs by (uid=0)
Apr 15 15:58:08 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user bbs by (uid=0)
Apr 15 15:58:08 bbs-sophos systemd-logind[883]: New session c2 of user bbs.
Apr 15 15:58:10 bbs-sophos dbus[851]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.54" (uid=0 pid=1379 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.7" (uid=0 pid=848 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 15 15:58:12 bbs-sophos gnome-keyring-daemon[1355]: The PKCS#11 component was already initialized
Apr 15 15:58:12 bbs-sophos gnome-keyring-daemon[1355]: The Secret Service was already initialized
Apr 15 15:58:14 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.80 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 15:58:38 bbs-sophos dbus[851]: [system] Failed to activate service 'org.bluez': timed out
Apr 15 15:59:23 bbs-sophos systemd-logind[883]: Removed session c1.
Apr 15 15:59:39 bbs-sophos polkit-agent-helper-1[2388]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 15:59:39 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.89 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 15 16:00:01 bbs-sophos CRON[2527]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 16:00:01 bbs-sophos CRON[2526]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 16:00:01 bbs-sophos CRON[2526]: pam_unix(cron:session): session closed for user smmsp
Apr 15 16:00:04 bbs-sophos CRON[2527]: pam_unix(cron:session): session closed for user root
Apr 15 16:00:12 bbs-sophos polkit-agent-helper-1[2669]: pam_unix(polkit-1:auth): authentication failure; logname= uid=1000 euid=0 tty= ruser=bbs rhost=  user=bbs
Apr 15 16:00:20 bbs-sophos polkit-agent-helper-1[2939]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 16:00:20 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:2664:24913 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:bbs)
Apr 15 16:00:20 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:00:20 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:00:20 bbs-sophos pkexec[2666]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/sbin/synaptic]
Apr 15 16:08:12 bbs-sophos polkit-agent-helper-1[3211]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 16:08:12 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain ONE-SHOT authorization for action com.ubuntu.pkexec.gufw for unix-process:3204:72862 [/bin/sh /usr/bin/gufw] (owned by unix-user:bbs)
Apr 15 16:08:12 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:08:12 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:08:12 bbs-sophos pkexec[3208]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/bin/gufw-pkexec bbs]
Apr 15 16:10:10 bbs-sophos polkit-agent-helper-1[3949]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 16:10:10 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain ONE-SHOT authorization for action com.ubuntu.pkexec.synaptic for unix-process:3943:84889 [/bin/sh /usr/bin/synaptic-pkexec] (owned by unix-user:bbs)
Apr 15 16:10:10 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:10:10 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:10:10 bbs-sophos pkexec[3945]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/sbin/synaptic]
Apr 15 16:15:01 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:8977:114390 (system bus name :1.107 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 16:15:01 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:8977:114390 (system bus name :1.107, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 16:15:19 bbs-sophos groupadd[9159]: group added to /etc/group: name=havp, GID=132
Apr 15 16:15:19 bbs-sophos groupadd[9159]: group added to /etc/gshadow: name=havp
Apr 15 16:15:19 bbs-sophos groupadd[9159]: new group: name=havp, GID=132
Apr 15 16:15:19 bbs-sophos useradd[9165]: new user: name=havp, UID=122, GID=132, home=/var/run/havp, shell=/bin/false
Apr 15 16:15:20 bbs-sophos usermod[9172]: change user 'havp' password
Apr 15 16:15:20 bbs-sophos chage[9179]: changed password expiry for havp
Apr 15 16:15:40 bbs-sophos groupadd[22432]: group added to /etc/group: name=clamav, GID=133
Apr 15 16:15:40 bbs-sophos groupadd[22432]: group added to /etc/gshadow: name=clamav
Apr 15 16:15:40 bbs-sophos groupadd[22432]: new group: name=clamav, GID=133
Apr 15 16:15:40 bbs-sophos useradd[22436]: new user: name=clamav, UID=123, GID=133, home=/var/lib/clamav, shell=/bin/false
Apr 15 16:15:41 bbs-sophos chage[22445]: changed password expiry for clamav
Apr 15 16:15:41 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:22454:118362 (system bus name :1.108 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 16:15:41 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:22454:118362 (system bus name :1.108, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 16:15:51 bbs-sophos groupadd[23080]: group added to /etc/group: name=clamsmtp, GID=134
Apr 15 16:15:51 bbs-sophos groupadd[23080]: group added to /etc/gshadow: name=clamsmtp
Apr 15 16:15:51 bbs-sophos groupadd[23080]: new group: name=clamsmtp, GID=134
Apr 15 16:15:51 bbs-sophos useradd[23084]: new user: name=clamsmtp, UID=124, GID=134, home=/var/spool/clamsmtp, shell=/bin/false
Apr 15 16:15:52 bbs-sophos chage[23089]: changed password expiry for clamsmtp
Apr 15 16:15:52 bbs-sophos gpasswd[23100]: user clamav added by root to group clamsmtp
Apr 15 16:16:15 bbs-sophos groupadd[23307]: group added to /etc/group: name=amavis, GID=135
Apr 15 16:16:15 bbs-sophos groupadd[23307]: group added to /etc/gshadow: name=amavis
Apr 15 16:16:15 bbs-sophos groupadd[23307]: new group: name=amavis, GID=135
Apr 15 16:16:15 bbs-sophos useradd[23313]: new user: name=amavis, UID=125, GID=135, home=/var/lib/amavis, shell=/bin/sh
Apr 15 16:16:16 bbs-sophos usermod[23320]: change user 'amavis' password
Apr 15 16:16:16 bbs-sophos chage[23325]: changed password expiry for amavis
Apr 15 16:16:16 bbs-sophos chfn[23328]: changed user 'amavis' information
Apr 15 16:16:21 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:23491:122404 (system bus name :1.109 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 15 16:16:21 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:23491:122404 (system bus name :1.109, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)
Apr 15 16:17:01 bbs-sophos CRON[23573]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 15 16:17:01 bbs-sophos CRON[23573]: pam_unix(cron:session): session closed for user root
Apr 15 16:20:01 bbs-sophos CRON[23798]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Apr 15 16:20:01 bbs-sophos CRON[23798]: pam_unix(cron:session): session closed for user smmsp
Apr 15 16:22:47 bbs-sophos polkit-agent-helper-1[24424]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 16:22:47 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.gnome.gnome-system-monitor.renice for unix-process:24400:159101 [gnome-system-monitor] (owned by unix-user:bbs)
Apr 15 16:22:47 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:22:47 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:22:47 bbs-sophos pkexec[24421]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 23698]
Apr 15 16:22:54 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:22:54 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:22:54 bbs-sophos pkexec[24436]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 23785]
Apr 15 16:23:02 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:23:02 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:23:02 bbs-sophos pkexec[24443]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 3204]
Apr 15 16:23:11 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:23:11 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:23:11 bbs-sophos pkexec[24452]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 2487]
Apr 15 16:23:15 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:23:15 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:23:15 bbs-sophos pkexec[24457]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 2183]
Apr 15 16:23:43 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:23:43 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:23:43 bbs-sophos pkexec[24479]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 23241]
Apr 15 16:24:25 bbs-sophos polkit-agent-helper-1[24507]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 15 16:24:25 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.gnome.gnome-system-monitor.kill for unix-process:24400:159101 [gnome-system-monitor] (owned by unix-user:bbs)
Apr 15 16:24:25 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:24:25 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:24:25 bbs-sophos pkexec[24504]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-kill -s 18 1194]
Apr 15 16:24:29 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:24:29 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:24:29 bbs-sophos pkexec[24517]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-kill -s 18 1024]
Apr 15 16:24:53 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:24:53 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:24:53 bbs-sophos pkexec[24534]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 2205]
Apr 15 16:24:57 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:24:57 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:24:57 bbs-sophos pkexec[24541]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice -20 2200]
Apr 15 16:25:34 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:25:34 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:25:34 bbs-sophos pkexec[24566]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice 19 888]
Apr 15 16:25:44 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:25:44 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:25:44 bbs-sophos pkexec[24575]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice 0 888]
Apr 15 16:26:00 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:26:00 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 15 16:26:00 bbs-sophos pkexec[24590]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/gnome-system-monitor/gnome-system-monitor/gsm-renice 19 837]
Apr 15 16:26:24 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 15 16:26:24 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session

bootlog

Code:

  /run/lvm/lvmetad.socket: connect failed: No such file or directory
  WARNING: Failed to connect to lvmetad. Falling back to internal scanning.
  Reading all physical volumes.  This may take a while...
  Found volume group "ubuntu-vg" using metadata type lvm2
  /run/lvm/lvmetad.socket: connect failed: No such file or directory
  WARNING: Failed to connect to lvmetad. Falling back to internal scanning.
  2 logical volume(s) in volume group "ubuntu-vg" now active
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
device-mapper: remove ioctl on sda5_crypt failed: Device or resource busy
Device sda5_crypt is still in use.
fsck from util-linux 2.26.2
/dev/mapper/ubuntu--vg-root: recovering journal
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512645 (uid=1000, gid=1000, mode=0100664, size=40960)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512614 (uid=1000, gid=1000, mode=0100600, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512510 (uid=1000, gid=1000, mode=0100664, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512615 (uid=1000, gid=1000, mode=0100664, size=40960)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24511684 (uid=1000, gid=1000, mode=0100600, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512613 (uid=1000, gid=1000, mode=0100664, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512535 (uid=1000, gid=1000, mode=0100664, size=40960)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512507 (uid=1000, gid=1000, mode=0100600, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512633 (uid=1000, gid=1000, mode=0100664, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597670 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597666 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597665 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597664 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597660 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597659 (uid=1000, gid=1000, mode=0100600, size=1024)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512554 (uid=1000, gid=1000, mode=0100664, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597663 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597662 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597661 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512655 (uid=1000, gid=1000, mode=0100664, size=40960)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512646 (uid=1000, gid=1000, mode=0100600, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24511850 (uid=1000, gid=1000, mode=0100664, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512561 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597658 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597657 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597656 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 26084606 (uid=0, gid=0, mode=0100644, size=231956)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597653 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597652 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597651 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512628 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597650 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597649 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597648 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 26745989 (uid=0, gid=0, mode=0100644, size=20852)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 25429002 (uid=0, gid=0, mode=0100644, size=134664)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597644 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597643 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597642 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597629 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597620 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597619 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24511834 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512542 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 26088132 (uid=0, gid=0, mode=0100644, size=230159)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597628 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597627 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597626 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597625 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597623 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597622 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512546 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24511799 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 26746549 (uid=0, gid=0, mode=0100644, size=20796)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 25429045 (uid=0, gid=0, mode=0100644, size=134348)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597612 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597611 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597608 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597607 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597606 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597605 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512547 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597602 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597601 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597600 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512524 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512540 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24511624 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512538 (uid=1000, gid=1000, mode=040700, size=4096)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512578 (uid=1000, gid=1000, mode=0100664, size=8192)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512573 (uid=1000, gid=1000, mode=0100664, size=8192)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512543 (uid=1000, gid=1000, mode=0100664, size=8192)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597599 (uid=1000, gid=1000, mode=0100600, size=16384)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597598 (uid=1000, gid=1000, mode=0100600, size=16384)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597595 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597594 (uid=1000, gid=1000, mode=0100600, size=32768)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597593 (uid=1000, gid=1000, mode=0100600, size=65536)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597592 (uid=1000, gid=1000, mode=0100600, size=1048576)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 15597591 (uid=1000, gid=1000, mode=0100600, size=1048576)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24510628 (uid=1000, gid=1000, mode=0100640, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24510672 (uid=1000, gid=1000, mode=0100640, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24510905 (uid=1000, gid=1000, mode=0100640, size=12288)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24510911 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24510921 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: Clearing orphaned inode 24512549 (uid=1000, gid=1000, mode=0100664, size=28672)
/dev/mapper/ubuntu--vg-root: clean, 270789/30253056 files, 7305684/120991744 blocks
[[0m[31m*    [0m] (1 of 8) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (41s / 5min 33s)
[K[[1;31m*[0m[31m*    [0m] (1 of 8) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (41s / 5min 33s)
[K[[31m*[1;31m*[0m[31m*  [0m] (1 of 8) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (42s / 5min 33s)
[K[ [31m*[1;31m*[0m[31m*  [0m] (2 of 8) A start job is running for Wait for Plymouth Boot Screen to Quit (42s / no limit)
[K[[32m  OK  [0m] Started LSB: Apache2 web server.
[  [31m*[1;31m*[0m[31m* [0m] (2 of 7) A start job is running for Wait for Plymouth Boot Screen to Quit (48s / no limit)
[K[  [31m*[1;31m*[0m[31m*[0m] (2 of 7) A start job is running for Wait for Plymouth Boot Screen to Quit (48s / no limit)
[K[    [31m*[1;31m*[0m] (3 of 7) A start job is running for LSB: HAVP virus-scanning HTTP proxy (49s / 5min 33s)
[K[    [31m*[0m] (3 of 7) A start job is running for LSB: HAVP virus-scanning HTTP proxy (49s / 5min 33s)
[K[    [31m*[1;31m*[0m] (3 of 7) A start job is running for LSB: HAVP virus-scanning HTTP proxy (50s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m*[0m] (4 of 7) A start job is running for LSB: Starts amavisd-new mailfilter (50s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m* [0m] (4 of 7) A start job is running for LSB: Starts amavisd-new mailfilter (51s / 5min 33s)
[K[ [31m*[1;31m*[0m[31m*  [0m] (4 of 7) A start job is running for LSB: Starts amavisd-new mailfilter (51s / 5min 33s)
[K[[31m*[1;31m*[0m[31m*  [0m] (5 of 7) A start job is running for Detect the available GPUs and deal with any system changes (52s / no limit)
[K[[1;31m*[0m[31m*    [0m] (5 of 7) A start job is running for Detect the available GPUs and deal with any system changes (52s / no limit)
[K[[0m[31m*    [0m] (5 of 7) A start job is running for Detect the available GPUs and deal with any system changes (53s / no limit)
[K[[1;31m*[0m[31m*    [0m] (6 of 7) A start job is running for LSB: start Samba daemons for the AD DC (53s / 5min 33s)
[K[[31m*[1;31m*[0m[31m*  [0m] (6 of 7) A start job is running for LSB: start Samba daemons for the AD DC (54s / 5min 33s)
[K[ [31m*[1;31m*[0m[31m*  [0m] (6 of 7) A start job is running for LSB: start Samba daemons for the AD DC (54s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m* [0m] (7 of 7) A start job is running for LSB: powerful, efficient, and scalable Mail Transport Agent (55s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m*[0m] (7 of 7) A start job is running for LSB: powerful, efficient, and scalable Mail Transport Agent (55s / 5min 33s)
[K[    [31m*[1;31m*[0m] (7 of 7) A start job is running for LSB: powerful, efficient, and scalable Mail Transport Agent (56s / 5min 33s)
[K[    [31m*[0m] (1 of 7) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (56s / 5min 33s)
[K[    [31m*[1;31m*[0m] (1 of 7) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (57s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m*[0m] (1 of 7) A start job is running for LSB: start Samba NetBIOS nameserver (nmbd) (57s / 5min 33s)
[K[  [31m*[1;31m*[0m[31m* [0m] (2 of 7) A start job is running for Wait for Plymouth Boot Screen to Quit (58s / no limit)
[K[ [31m*[1;31m*[0m[31m*  [0m] (2 of 7) A start job is running for Wait for Plymouth Boot Screen to Quit (58s / no limit)
[K[[31m*[1;31m*[0m[31m*  [0m] (2 of 7) A start job is running for Wait for Plymouth Boot Screen to Quit (59s / no limit)
[K[[1;31m*[0m[31m*    [0m] (3 of 7) A start job is running for LSB: HAVP virus-scanning HTTP proxy (59s / 5min 33s)
[K[[0m[31m*    [0m] (3 of 7) A start job is running for LSB: HAVP virus-scanning HTTP proxy (1min / 5min 33s)
[K[[1;31mFAILED[0m] Failed to start LSB: Starts amavisd-new mailfilter.
See 'systemctl status amavis.service' for details.
[[32m  OK  [0m] Started LSB: start Samba daemons for the AD DC.
[[32m  OK  [0m] Started LSB: start Samba NetBIOS nameserver (nmbd).
        Starting LSB: start Samba SMB/CIFS daemon (smbd)...
[[32m  OK  [0m] Started LSB: start Samba SMB/CIFS daemon (smbd).
[[32m  OK  [0m] Started Detect the available GPUs and deal with any system changes.
        Starting Light Display Manager...

Authlos Teil 2

Code:


Apr 14 19:33:47 bbs-sophos polkit-agent-helper-1[2617]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 19:33:47 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.89 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 14 19:39:36 bbs-sophos polkit-agent-helper-1[6132]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 19:39:36 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.89 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 14 19:48:22 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny ipp14
Apr 14 19:48:22 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:48:22 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:48:32 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny ipps
Apr 14 19:48:32 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:48:32 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:48:44 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny LDP
Apr 14 19:48:44 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:48:44 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:48:53 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny lpd
Apr 14 19:48:53 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:48:54 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:49:13 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny 9100
Apr 14 19:49:13 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:49:13 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:49:53 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/sbin/ufw deny CUPS
Apr 14 19:49:53 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 19:49:53 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 19:52:27 bbs-sophos polkit-agent-helper-1[10706]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 19:52:27 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action com.ubuntu.softwareproperties.applychanges for system-bus-name::1.115 [/usr/bin/python3 /usr/bin/software-properties-gtk] (owned by unix-user:bbs)
Apr 14 19:58:34 bbs-sophos polkit-agent-helper-1[11476]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 19:58:34 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.119 [/usr/bin/python3 /usr/bin/gnome-language-selector] (owned by unix-user:bbs)
Apr 14 20:00:04 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 14 20:00:04 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 14 20:00:04 bbs-sophos pkexec[12385]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Apr 14 20:02:21 bbs-sophos dbus[693]: [system] Failed to activate service 'org.bluez': timed out
Apr 14 20:05:10 bbs-sophos polkit-agent-helper-1[12717]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 20:05:10 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action com.ubuntu.softwareproperties.applychanges for system-bus-name::1.134 [/usr/bin/python3 /usr/bin/software-properties-gtk --open-tab 2 --toplevel 62914567] (owned by unix-user:bbs)
Apr 14 20:05:22 bbs-sophos systemd-logind[745]: System is rebooting.
Apr 14 20:09:35 bbs-sophos systemd-logind[785]: New seat seat0.
Apr 14 20:09:35 bbs-sophos systemd-logind[785]: Watching system buttons on /dev/input/event2 (Power Button)
Apr 14 20:09:35 bbs-sophos systemd-logind[785]: Watching system buttons on /dev/input/event3 (Video Bus)
Apr 14 20:09:35 bbs-sophos systemd-logind[785]: Watching system buttons on /dev/input/event0 (Power Button)
Apr 14 20:09:35 bbs-sophos systemd-logind[785]: Watching system buttons on /dev/input/event1 (Sleep Button)
Apr 14 20:09:40 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 14 20:09:40 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 14 20:09:40 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 14 20:09:40 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 14 20:09:40 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
Apr 14 20:09:40 bbs-sophos systemd-logind[785]: New session c1 of user lightdm.
Apr 14 20:09:40 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user lightdm by (uid=0)
Apr 14 20:09:44 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
Apr 14 20:09:44 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet.so
Apr 14 20:09:44 bbs-sophos lightdm: PAM unable to dlopen(pam_kwallet5.so): /lib/security/pam_kwallet5.so: cannot open shared object file: No such file or directory
Apr 14 20:09:44 bbs-sophos lightdm: PAM adding faulty module: pam_kwallet5.so
Apr 14 20:09:44 bbs-sophos lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "bbs"
Apr 14 20:10:09 bbs-sophos dbus[789]: [system] Failed to activate service 'org.bluez': timed out
Apr 14 20:10:14 bbs-sophos lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
Apr 14 20:10:14 bbs-sophos lightdm: pam_unix(lightdm:session): session opened for user bbs by (uid=0)
Apr 14 20:10:14 bbs-sophos systemd-logind[785]: New session c2 of user bbs.
Apr 14 20:10:14 bbs-sophos systemd: pam_unix(systemd-user:session): session opened for user bbs by (uid=0)
Apr 14 20:10:16 bbs-sophos gnome-keyring-daemon[1094]: The Secret Service was already initialized
Apr 14 20:10:16 bbs-sophos gnome-keyring-daemon[1094]: The SSH agent was already initialized
Apr 14 20:10:16 bbs-sophos gnome-keyring-daemon[1094]: The PKCS#11 component was already initialized
Apr 14 20:10:17 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-session:c2 (system bus name :1.63 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:10:41 bbs-sophos dbus[789]: [system] Failed to activate service 'org.bluez': timed out
Apr 14 20:11:31 bbs-sophos dbus[789]: [system] Rejected send message, 7 matched rules; type="method_call", sender=":1.90" (uid=1000 pid=1896 comm="/usr/bin/python /usr/lib/ubuntu-sso-client/ubuntu-") interface="(unset)" member="Get" error name="(unset)" requested_reply="0" destination="org.freedesktop.NetworkManager" (uid=0 pid=821 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 14 20:11:41 bbs-sophos systemd-logind[785]: Removed session c1.
Apr 14 20:11:41 bbs-sophos systemd: pam_unix(systemd-user:session): session closed for user lightdm
Apr 14 20:14:30 bbs-sophos polkit-agent-helper-1[1996]: pam_unix(polkit-1:auth): authentication failure; logname= uid=1000 euid=0 tty= ruser=bbs rhost=  user=bbs
Apr 14 20:14:37 bbs-sophos polkit-agent-helper-1[1997]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 20:14:37 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.change-repository for system-bus-name::1.86 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 14 20:14:48 bbs-sophos dbus[789]: [system] Rejected send message, 7 matched rules; type="method_call", sender=":1.94" (uid=1000 pid=2042 comm="/usr/bin/python /usr/lib/ubuntu-sso-client/ubuntu-") interface="(unset)" member="Get" error name="(unset)" requested_reply="0" destination="org.freedesktop.NetworkManager" (uid=0 pid=821 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 14 20:17:01 bbs-sophos CRON[2464]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 14 20:17:01 bbs-sophos CRON[2464]: pam_unix(cron:session): session closed for user root
Apr 14 20:18:56 bbs-sophos dbus[789]: [system] Rejected send message, 10 matched rules; type="method_return", sender=":1.110" (uid=0 pid=2526 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.7" (uid=0 pid=821 comm="/usr/sbin/NetworkManager --no-daemon ")
Apr 14 20:22:27 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 FAILED to authenticate to gain authorization for action org.debian.apt.change-repository for system-bus-name::1.86 [/usr/bin/python /usr/bin/software-center] (owned by unix-user:bbs)
Apr 14 20:28:01 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install language-pack-de
Apr 14 20:28:01 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 20:28:01 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 20:30:48 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install apturl
Apr 14 20:30:48 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 20:30:48 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 20:31:19 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install language-pack-de
Apr 14 20:31:19 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 20:31:19 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 20:31:37 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get autoremove
Apr 14 20:31:37 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 20:34:02 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 20:36:15 bbs-sophos sudo:      bbs : TTY=pts/1 ; PWD=/home/bbs ; USER=root ; COMMAND=/usr/bin/apt-get install language-pack-de
Apr 14 20:36:15 bbs-sophos sudo: pam_unix(sudo:session): session opened for user root by bbs(uid=0)
Apr 14 20:36:15 bbs-sophos sudo: pam_unix(sudo:session): session closed for user root
Apr 14 20:39:39 bbs-sophos polkit-agent-helper-1[5760]: pam_ecryptfs: pam_sm_authenticate: /home/bbs is already mounted
Apr 14 20:39:39 bbs-sophos polkitd(authority=local): Operator of unix-session:c2 successfully authenticated as unix-user:bbs to gain TEMPORARY authorization for action org.debian.apt.install-or-remove-packages for system-bus-name::1.119 [/usr/bin/python3 /usr/bin/update-manager] (owned by unix-user:bbs)
Apr 14 20:41:19 bbs-sophos pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1000)
Apr 14 20:41:19 bbs-sophos pkexec: pam_systemd(polkit-1:session): Cannot create session: Already running in a session
Apr 14 20:41:19 bbs-sophos pkexec[5784]: bbs: Executing command [USER=root] [TTY=unknown] [CWD=/home/bbs] [COMMAND=/usr/lib/update-notifier/package-system-locked]
Apr 14 20:43:40 bbs-sophos polkitd(authority=local): Registered Authentication Agent for unix-process:14682:228282 (system bus name :1.127 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8)
Apr 14 20:43:40 bbs-sophos polkitd(authority=local): Unregistered Authentication Agent for unix-process:14682:228282 (system bus name :1.127, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale de_DE.UTF-8) (disconnected from bus)

Clam log.
Clam läuft überhaupt nicht, logs werden meist nicht erstellt, obwohl in config aktiviert und neuste version, dann werden ordner einfach ausgelassen, die ich zum scannen gewählt habe, Infizierte Datein kann ich nicht löschen oder in Quarantäne verschieben.

Trotzdem hier ein Log mit möglichen Infekten (fett)


Code:


-------------------------------------------------------------------------------


----------- SCAN SUMMARY -----------
Known viruses: 4303757
Engine version: 0.98.7
Scanned directories: 475
Scanned files: 1711
Infected files: 0
Total errors: 3
Data scanned: 271.81 MB
Data read: 14823.12 MB (ratio 0.02:1)
Time: 48.963 sec (0 m 48 s)

ClamTk, v5.19
Sat Apr 16 01:38:46 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:
/etc/suricata/rules
/lib/firmware/vxge
/usr/lib/mono/4.0
/usr/lib/mono/4.5
/usr/share/clamav-testfiles
/usr/share/mime

47 wahrscheinlich infizierte Bedrohungen gefunden (163333 Dateien untersucht).

/usr/share/clamav-testfiles/clam.sis                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ea05.exe            PUA.Win.Packer.Upx-48                     
/usr/share/clamav-testfiles/clam.newc.cpio          PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ppt                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.bin-be.cpio        PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-pespin.exe          PUA.Win.Packer.PESpin-1                   
/usr/share/clamav-testfiles/clam.pdf                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.binhex          PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.tar.gz              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_IScab_int.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-aspack.exe          PUA.Win.Packer.Asprotect-3               
/usr/share/clamav-testfiles/clam-nsis.exe            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.szdd            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_cache_emax.tgz      Clamav.Test.File-6                       
/usr/share/clamav-testfiles/clam_ISmsi_ext.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-yc.exe              PUA.Win.Packer.ExeshieldCrypto-1         
/usr/share/clamav-testfiles/clam-upack.exe          PUA.Win.Packer.UPack-3                   
/usr/share/clamav-testfiles/clam.cab                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ole.doc            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ea06.exe            PUA.Win.Packer.Upx-48                     
/usr/share/clamav-testfiles/clam.zip                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.bz2            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-fsg.exe            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.7z                  PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.rtf            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-upx.exe            PUA.Win.Packer.Upx-29                     
/usr/share/clamav-testfiles/clam.impl.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.chm                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-petite.exe          PUA.Win.Packer.Petite-1                   
/usr/share/clamav-testfiles/clam.bin-le.cpio        PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.bz2.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.arj                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-v2.rar              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_ISmsi_int.exe      PUA.Win.Packer.SetupExeSection-1         
/usr/share/clamav-testfiles/clam_IScab_ext.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/mime/mime.cache                          PUA.Win.Exploit.CVE_2012_0110-1           
/usr/lib/mono/4.5/mscorlib.dll                      PUA.Win.Packer.PrivateExeProte-8         
/usr/lib/mono/4.0/mscorlib.dll                      PUA.Win.Packer.PrivateExeProte-8         
/etc/suricata/rules/emerging-web_server.rules        PUA.Html.Trojan.Crypt-355                 
/etc/suricata/rules/emerging-deleted.rules          Html.Trojan.Blackhole-65                 
/etc/suricata/rules/emerging-activex.rules          PUA.Win.Tool.ActiveX_CVE_2009_1671-1     
/usr/share/clamav-testfiles/clam-v3.rar              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-wwpack.exe          PUA.Win.Packer.Mslrh-35                   
/usr/share/clamav-testfiles/clam.odc.cpio            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-mew.exe            PUA.Win.Packer.MEW-1                     
/usr/share/clamav-testfiles/clam.d64.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
----------------------------------------------------------------------------------------------------

ClamTk, v5.19
Sat Apr 16 03:48:31 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:

0 wahrscheinlich infizierte Bedrohungen gefunden (1 Datei untersucht).

Keine Bedrohungen gefunden.
---------------------------------------------

ClamTk, v5.19
Sat Apr 16 04:42:42 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:
/media/bbs/WIN/2/Neuer Ordner
/media/bbs/WIN/7
/media/bbs/WIN/8

0 wahrscheinlich infizierte Bedrohungen gefunden (2446 Dateien untersucht).

Keine Bedrohungen gefunden.
---------------------------------------------

ClamTk, v5.19
Sat Apr 16 04:45:04 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:

0 wahrscheinlich infizierte Bedrohungen gefunden (1 Datei untersucht).

Keine Bedrohungen gefunden.
---------------------------------------------

ClamTk, v5.19
Sat Apr 16 04:46:50 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:

0 wahrscheinlich infizierte Bedrohungen gefunden (1 Datei untersucht).

Keine Bedrohungen gefunden.
---------------------------------------------

ClamTk, v5.19
Sat Apr 16 06:52:13 2016
ClamAV-Signaturen: 4304101
Untersuchte Verzeichnisse:
/etc/suricata/rules
/lib/firmware/vxge
/usr/lib/mono/4.0
/usr/lib/mono/4.5
/usr/share/clamav-testfiles
/usr/share/mime

47 wahrscheinlich infizierte Bedrohungen gefunden (181162 Dateien untersucht).

/usr/share/clamav-testfiles/clam.sis                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ea05.exe            PUA.Win.Packer.Upx-48                     
/usr/share/clamav-testfiles/clam.newc.cpio          PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ppt                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.bin-be.cpio        PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-pespin.exe          PUA.Win.Packer.PESpin-1                   
/usr/share/clamav-testfiles/clam.pdf                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.binhex          PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.tar.gz              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_IScab_int.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-aspack.exe          PUA.Win.Packer.Asprotect-3               
/usr/share/clamav-testfiles/clam-nsis.exe            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.szdd            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_cache_emax.tgz      Clamav.Test.File-6                       
/usr/share/clamav-testfiles/clam_ISmsi_ext.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-yc.exe              PUA.Win.Packer.ExeshieldCrypto-1         
/usr/share/clamav-testfiles/clam-upack.exe          PUA.Win.Packer.UPack-3                   
/usr/share/clamav-testfiles/clam.cab                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ole.doc            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.ea06.exe            PUA.Win.Packer.Upx-48                     
/usr/share/clamav-testfiles/clam.zip                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.bz2            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-fsg.exe            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.7z                  PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.exe.rtf            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-upx.exe            PUA.Win.Packer.Upx-29                     
/usr/share/clamav-testfiles/clam.impl.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.chm                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-petite.exe          PUA.Win.Packer.Petite-1                   
/usr/share/clamav-testfiles/clam.bin-le.cpio        PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.bz2.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam.arj                PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-v2.rar              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam_ISmsi_int.exe      PUA.Win.Packer.SetupExeSection-1         
/usr/share/clamav-testfiles/clam_IScab_ext.exe      PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/mime/mime.cache                          PUA.Win.Exploit.CVE_2012_0110-1           
/usr/lib/mono/4.5/mscorlib.dll                      PUA.Win.Packer.PrivateExeProte-8         
/usr/lib/mono/4.0/mscorlib.dll                      PUA.Win.Packer.PrivateExeProte-8 
       
/etc/suricata/rules/emerging-web_server.rules        PUA.Html.Trojan.Crypt-355                 
/etc/suricata/rules/emerging-deleted.rules          Html.Trojan.Blackhole-65
                 
/etc/suricata/rules/emerging-activex.rules          PUA.Win.Tool.ActiveX_CVE_2009_1671-1     
/usr/share/clamav-testfiles/clam-v3.rar              PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-wwpack.exe          PUA.Win.Packer.Mslrh-35                   
/usr/share/clamav-testfiles/clam.odc.cpio            PUA.Win.Packer.AcprotectUltraprotect-1   
/usr/share/clamav-testfiles/clam-mew.exe            PUA.Win.Packer.MEW-1                     
/usr/share/clamav-testfiles/clam.d64.zip            PUA.Win.Packer.AcprotectUltraprotect-1   
----------------------------------------------------------------------------------------------------



chkrootkit
Code:

bbs@bbs-sophos:~$ sudo chkrootkit
[sudo] Passwort für bbs:
ROOTDIR is `/'
Checking `amd'...                                          not found
Checking `basename'...                                      not infected
Checking `biff'...                                          not found
Checking `chfn'...                                          not infected
Checking `chsh'...                                          not infected
Checking `cron'...                                          not infected
Checking `crontab'...                                      not infected
Checking `date'...                                          not infected
Checking `du'...                                            not infected
Checking `dirname'...                                      not infected
Checking `echo'...                                          not infected
Checking `egrep'...                                        not infected
Checking `env'...                                          not infected
Checking `find'...                                          not infected
Checking `fingerd'...                                      not found
Checking `gpm'...                                          not found
Checking `grep'...                                          not infected
Checking `hdparm'...                                        not infected
Checking `su'...                                            not infected
Checking `ifconfig'...                                      not infected
Checking `inetd'...                                        not infected
Checking `inetdconf'...                                    not found
Checking `identd'...                                        not found
Checking `init'...                                          not infected
Checking `killall'...                                      not infected
Checking `ldsopreload'...                                  not infected
Checking `login'...                                        not infected
Checking `ls'...                                            not infected
Checking `lsof'...                                          not infected
Checking `mail'...                                          not infected
Checking `mingetty'...                                      not found
Checking `netstat'...                                      not infected
Checking `named'...                                        not found
Checking `passwd'...                                        not infected
Checking `pidof'...                                        not infected
Checking `pop2'...                                          not found
Checking `pop3'...                                          not found
Checking `ps'...                                            not infected
Checking `pstree'...                                        not infected
Checking `rpcinfo'...                                      not found
Checking `rlogind'...                                      not found
Checking `rshd'...                                          not found
Checking `slogin'...                                        not infected
Checking `sendmail'...                                      not infected
Checking `sshd'...                                          not found
Checking `syslogd'...                                      not tested
Checking `tar'...                                          not infected
Checking `tcpd'...                                          not infected
Checking `tcpdump'...                                      not infected
Checking `top'...                                          not infected
Checking `telnetd'...                                      not found
Checking `timed'...                                        not found
Checking `traceroute'...                                    not found
Checking `vdir'...                                          not infected
Checking `w'...                                            not infected
Checking `write'...                                        not infected
Checking `aliens'...                                        no suspect files
Searching for sniffer's logs, it may take a while...       
nothing found
Searching for rootkit HiDrootkit's default files...        nothing found
Searching for rootkit t0rn's default files...              nothing found
Searching for t0rn's v8 defaults...                       
nothing found
Searching for rootkit Lion's default files...              nothing found
Searching for rootkit RSHA's default files...              nothing found
Searching for rootkit RH-Sharpe's default files...          nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found: 
/usr/lib/python2.7/dist-packages/PyQt4/uic/widget-plugins/.noinit /lib/modules/4.2.0-35-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id
/lib/modules/4.2.0-35-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id

Searching for LPD Worm files and dirs...                    nothing found
Searching for Ramen Worm files and dirs...                  nothing found
Searching for Maniac files and dirs...                      nothing found
Searching for RK17 files and dirs...                        nothing found
Searching for Ducoci rootkit...                            nothing found
Searching for Adore Worm...                                nothing found
Searching for ShitC Worm...                                nothing found
Searching for Omega Worm...                                nothing found
Searching for Sadmind/IIS Worm...                          nothing found
Searching for MonKit...                                    nothing found
Searching for Showtee...                                    nothing found
Searching for OpticKit...                                  nothing found
Searching for T.R.K...                                      nothing found
Searching for Mithra...                                    nothing found
Searching for LOC rootkit...                                nothing found
Searching for Romanian rootkit...                          nothing found
Searching for Suckit rootkit...                            nothing found
Searching for Volc rootkit...                              nothing found
Searching for Gold2 rootkit...                              nothing found
Searching for TC2 Worm default files and dirs...            nothing found
Searching for Anonoying rootkit default files and dirs...  nothing found
Searching for ZK rootkit default files and dirs...          nothing found
Searching for ShKit rootkit default files and dirs...      nothing found
Searching for AjaKit rootkit default files and dirs...      nothing found
Searching for zaRwT rootkit default files and dirs...      nothing found
Searching for Madalin rootkit default files...              nothing found
Searching for Fu rootkit default files...                  nothing found
Searching for ESRK rootkit default files...                nothing found
Searching for rootedoor...                                  nothing found
Searching for ENYELKM rootkit default files...              nothing found
Searching for common ssh-scanners default files...          nothing found
Searching for Linux/Ebury - Operation Windigo ssh...        Possible Linux/Ebury - Operation Windigo installetd
Searching for 64-bit Linux Rootkit ...                      nothing found
Searching for 64-bit Linux Rootkit modules...              nothing found
Searching for suspect PHP files...                          nothing found
Searching for anomalies in shell history files...          nothing found
Checking `asp'...                                          not infected
Checking `bindshell'...                                    not infected
Checking `lkm'...                                          You have    3 process hidden for readdir command
You have    3 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed



chkdirs: nothing detected
Checking `rexedcs'...                                      not found
Checking `sniffer'...                                      lo: not promisc and no packet sniffer sockets
enp3s0: PACKET SNIFFER(/sbin/dhclient[6636])
Checking `w55808'...                                        not infected
Checking `wted'...                                          chkwtmp: nothing deleted
Checking `scalper'...                                      not infected
Checking `slapper'...                                      not infected
Checking `z2'...                                            user bbs deleted or never logged from lastlog!
user root deleted or never logged from lastlog!
Checking `chkutmp'...                                        The tty of the following user process(es) were not found
 in /var/run/utmp !
! RUID          PID TTY    CMD
! root        1164 tty7  /usr/bin/X -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
chkutmp: nothing deleted
Checking `OSX_RSPLUG'...                                    not infected

Im Übrigen: Übuntu gestern auf einer NEUEN Festplatte neu aufgesetzt (kein heruntergeladenes Image, sondern mit einer nicht wieder beschreibbaren CD von einer offiziellen Quelle installiert).

Zudem: keine Software aus dritten Quellen installiert (Außnahme: Cryptkeeper/ Clam von offiziellen Quellen), keine neuen Benutzer angelegt oder bestehende konfiguriert, kein ssh, cups, samba, VNC, rdp, bluetooth, filesharing oder sonstigen Schnickschnack konfiguriert oder genutzt.
Sufen und VirtualBox waren die Hauptaktivitären (Win10 Iso direkt von Mircosoft).

Dante12 16.04.2016 09:55

Du verwendest tools die nachweislich Fehlalarme erzeugen. Alle Dateien die du dort aufgelistet hast sind nicht infiziert.

Zitat:

/usr/share/mime/mime.cache PUA.Win.Exploit.CVE_2012_0110-1
Das ist eine generierte Datei die alle bekannten Mime-Typen enthält und ist nicht ausführbar!

https://wiki.ubuntuusers.de/MIME-Typ/

... sind Bestandteile von Mono. Das einzige was du damit bewirkst wenn du sie löscht ist, dass du mono neu Aufsetzen musst. Die PUA-Funktion von ClamAV ist fehlerhaft und ist Standardmässig deaktiviert. Ich nehme mal an das du es selbst aktiviert hast?

Zitat:

/usr/lib/mono/4.5/mscorlib.dll PUA.Win.Packer.PrivateExeProte-8
/usr/lib/mono/4.0/mscorlib.dll PUA.Win.Packer.PrivateExeProte-8
https://www.virustotal.com/de/file/4...is/1423563969/

Zitat:

/etc/suricata/rules/emerging-web_server.rules PUA.Html.Trojan.Crypt-355
/etc/suricata/rules/emerging-deleted.rules Html.Trojan.Blackhole-65
/etc/suricata/rules/emerging-activex.rules PUA.Win.Tool.ActiveX_CVE_2009_1671-1
Das gehört doch nicht zu Standardinstallation von Ubuntu oder irre ich da. Das hast du doch selbst installiert oder? . Suricata ist ein Intrusion detection System, also wird jedes AV auch wenn es noch so schlecht ist darauf anschlagen.

Zitat:

/usr/lib/python2.7/dist-packages/PyQt4/uic/widget-plugins/.noinit /lib/modules/4.2.0-35-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id
/lib/modules/4.2.0-35-generic/vdso/.build-id /lib/modules/4.2.0-16-generic/vdso/.build-id
Sind Bestanteile des Systems.

Zitat:

Searching for Linux/Ebury - Operation Windigo ssh... Possible Linux/Ebury - Operation Windigo installetd
Nochmal, selbst für gute AVs ist es schwer Ebury eindeutig zu identifizieren. Hier meldet dein AV eine mögliche Ebury-Infektion die keine ist. Ein Bestandteil von Ubuntu sind die atm-tools und beinhalteten ähnliche Funktionalitäten wie Ebury, nur das diese für ganz andere Aufgaben zuständig sind.

...und das ist das beste :D
Zitat:

enp3s0: PACKET SNIFFER(/sbin/dhclient[6636])
Lass den mal von deinem AV löschen und schwups hast du kein Netz mehr.

Ubuntu Manpage: dhclient - Dynamic Host Configuration Protocol Client

Bevor du also weiterhin mit panischen Attacken nach Infektionen suchst die gar keine sind, solltest du dich mal hinsetzen und ein wenig über forensische Analyse bei Malware und Reverse Engineering in Erfahrung bringen. Denn dieses wilde posten von Logs ohne selbst eine konkrete Vermutung oder Untersuchung anzustellen -oder zumindest selbst aktiv zu werden - postest du munter weiter.

PS: ...und mehr über die Sicherheit von Unix/Linux Systemen in Erfahrung bringen. Denn wären diese wirklich so Anfällig wie es deine Logs beschreiben würden, dann wären sie nicht Weltweit die Standards für Server-Applikationen.

W_Dackel 16.04.2016 18:32

Kurzfassung: du verwendest die Tools falsch und bist panikartig auf Gespensterjagd. Ein Ubuntu in der Standardinstallation ist schonmal ziemlich sicher, lehn dich zurück und arbeite dich erst in Linux, dann in diese Tools ein bevor du weiter Panik schiebst.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:39 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130