Ok also ich poste mal die Stellen aus dem LOG die ich als Fehler deuten würde:
[22:31:56] Info: Unable to find the 'ldd' command
[22:31:57] Info: Unable to find the 'lsattr' command
[22:31:57] Info: Unable to find the 'pgrep' command
[22:31:57] Info: Unable to find the 'strings' command
[22:31:57] Info: Stored hash values used hash function '/opt/bin/sha1sum'
[22:31:57] Info: Stored hash values did not use a package manager
[22:31:57] Info: The hash function field index is set to 1
[22:31:57] Info: No package manager specified: using hash function '/opt/bin/sha1sum'
[22:31:58] Checking 'strings' command [ Skipped ]
[22:31:58] Info: Unable to find the 'strings' command
[22:31:58] Checking for preloaded libraries [ None found ]
[22:31:58] Info: Starting test name 'properties'
[22:31:58] Performing file properties checks
[22:31:58] Warning: Checking for prerequisites [ Warning ]
[22:31:58] Unable to find 'lsattr' command - all file immutable-bit checks will be skipped.
Nun kommen, so wie ich es verstehe, die Überprüfung ob RootKits gefunden werden. Da steht jeweils Not found, was ja ein gutes Zeichen erstmal ist
Dann wieder:
[22:33:31] Checking process list for process 'ata/0' [ Skipped ]
[22:33:31] Info: Unable to find the 'pgrep' command
[22:34:06] Info: Starting test name 'deleted_files'
[22:34:09] Checking running processes for deleted files [ Warning ]
[22:34:09] Warning: The following processes are using deleted files:
[22:34:09] Process: /volume1/@appstore/CloudStation/sbin/syncd PID: 8859 File: /tmp/etilqs_4WbRdahyAAk78wF
[22:34:09] Info: Starting test name 'running_procs'
[22:34:12] Checking running processes for suspicious files [ None found ]
[22:34:12]
[22:34:12] Info: Starting test name 'hidden_procs'
[22:34:12] Info: Unable to find the 'unhide' command
[22:34:12] Info: Unable to find the 'unhide-linux26' command
[22:34:12] Info: Unable to find the 'unhide.rb' command
[22:34:12] Checking for hidden processes [ Skipped ]
[22:34:13] Checking for software intrusions [ Skipped ]
[22:34:13] Info: Check skipped - tripwire not installed
[22:34:13] Performing check for enabled xinetd services
[22:34:13] Checking for enabled xinetd services [ Skipped ]
[22:34:17] Info: Starting test name 'hidden_ports'
[22:34:17] Checking for hidden ports [ Skipped ]
[22:34:17] Info: Unable to find the 'unhide-tcp' command
[22:34:20] Checking if SSH root access is allowed [ Warning ]
[22:34:20] Warning: The SSH configuration option 'PermitRootLogin' has not been set.
The default value may be 'yes', to allow root access.
[22:34:20] Checking if SSH protocol v1 is allowed [ Warning ]
[22:34:20] Warning: The SSH configuration option 'Protocol' has not been set.
The default value may be '2,1', to allow the use of protocol version 1.
[22:34:20] Checking for running syslog daemon [ Warning ]
[22:34:20] Warning: The syslog daemon is not running.
[22:34:21] Info: Starting test name 'filesystem'
[22:34:21] Performing filesystem checks
[22:34:21] Info: SCAN_MODE_DEV set to 'THOROUGH'
[22:34:21] Checking /dev for suspicious file types [ Warning ]
[22:34:21] Warning: Suspicious file types found in /dev:
[22:34:21] /dev/.mdadm/map: ASCII text
[22:34:21] Checking for hidden files and directories [ Warning ]
[22:34:21] Warning: Hidden directory found: '/dev/.mdadm'
Ich weiß sehr viel. Aber ich konnte jetzt schwierig unterscheiden, was für dich nun von Relevanz ist und was nicht.