You are Here:
Linux Lite 6.6 FINAL Released - Support for 22 Languages Added - See Release Announcement Section



z2 and message in chkrootkit

Author (Read 2717 times)

0 Members and 1 Guest are viewing this topic.

Re: z2 and message in chkrootkit
« Reply #3 on: December 05, 2017, 08:20:10 AM »
 

ian_r_h

  • Merchandise Supporter
  • Forum Regular
  • *****
  • 103
    Posts
  • Reputation: 10
  • Linux Lite Member
    • View Profile
Thanks, TC.
Don't worry about artificial intelligence.  Worry about natural stupidity.  :)
 

Re: z2 and message in chkrootkit
« Reply #2 on: December 04, 2017, 07:14:48 AM »
 

trinidad

  • Platinum Level Poster
  • **********
  • 1471
    Posts
  • Reputation: 214
  • Linux Lite Member
    • View Profile
    • dbts-analytics.com

  • CPU: i7 4 cores 8 threads

  • MEMORY: 16Gb

  • VIDEO CARD: Intel HD graphics

  • Kernel: 5.x
I believe z2 refers to a backgrounded process error message, 2 being the error status and z referring to its being a backgrounded process.

Here you go:

http://write.flossmanuals.net/command-line/processes/

TC
« Last Edit: December 04, 2017, 07:19:47 AM by trinidad »
All opinions expressed and all advice given by Trinidad Cruz on this forum are his responsibility alone and do not necessarily reflect the views or methods of the developers of Linux Lite. He is a citizen of the United States where it is acceptable to occasionally be uninformed and inept as long as you pay your taxes.
 

z2 and message in chkrootkit
« Reply #1 on: December 04, 2017, 05:49:18 AM »
 

ian_r_h

  • Merchandise Supporter
  • Forum Regular
  • *****
  • 103
    Posts
  • Reputation: 10
  • Linux Lite Member
    • View Profile
Hi, all,

I've installed chkrootkit on one of my units; but some time after the initial build rather than straightaway as I would have liked to have done (in order to establish a baseline for a fresh build).

I've got one line which I don't understand, and which I've drawn a blank when Googling and am hoping someone might be able to give me some pointers:

Checking `z2'...                                            user ian deleted or never logged from lastlog!

Does anyone know to what "z2" is referring?
I'm unfamiliar with the lastlog command also, being new to the terminal, etc.

I don't think it's necessarily related, but I also get a strange entry under

Checking `chkutmp'...                                        The tty of the following user process(es) were not found
 in /var/run/utmp !

Which looks like some form of bug(?) in chkrootkit, when connected to the Internet (and in this case running firefox  which returns 57.0.1 64-bit in firejail):

! RUID          PID TTY    CMD
! �⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire       0 ‧ ??? ??? ? ‹›⁁⁄⁒ ⅓�⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire �⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire
! �⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire       0 ‧ ??? ??? ? ‹›⁁⁄⁒ ⅓�⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire �⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire
! �⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire       0 ‧ ??? ??? ? ‹›⁁⁄⁒ ⅓�⅙⅚?⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire �⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞?./。ᅠ ??? �|159:4;high| -schedulerPrefs 0001,2 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/fire

before more expected entries which generally seem to refer to running chkrootkit as sudo:

! ian         31063 pts/4  /bin/bash
! root        31070 pts/4  /bin/sh /usr/sbin/chkrootkit
! root        31726 pts/4  ./chkutmp
! root        31728 pts/4  ps axk tty,ruser,args -o tty,pid,ruser,args
! root        31727 pts/4  sh -c ps axk "tty,ruser,args" -o "tty,pid,ruser,args"
! root        31069 pts/4  sudo chkrootkit
chkutmp: nothing deleted

Thanks all,
Ian
« Last Edit: December 08, 2017, 02:54:22 AM by Jerry »
Don't worry about artificial intelligence.  Worry about natural stupidity.  :)
 

 

-->
X Close Ad

Linux Lite 6.6 FINAL Released - Support for 22 Languages Added - See Release Announcement Section