Rkhunter /dev suspicious detection

hello i what do ? just remove this files?
[12:57:18] Info: SCAN_MODE_DEV set to ‘THOROUGH’
[12:57:27] Checking /dev for suspicious file types [ Warning ]
[12:57:27] Warning: Suspicious file types found in /dev:
[12:57:27] /dev/shm/jack_db/metadata.db: Berkeley DB (Hash, version 9, native byte-order)
[12:57:27] /dev/shm/jack_db/__db.003: a.out little-endian 32-bit pure executable
[12:57:27] /dev/shm/jack_db/__db.002: a.out little-endian 32-bit pure executable
[12:57:27] /dev/shm/jack_db/__db.001: Applesoft BASIC program data, first line number 18
[12:57:27] Checking for hidden files and directories [ Warning ]
[12:57:27] Warning: Hidden file found: /etc/.updated: ASCII text
[12:57:28] Warning: Hidden file found: /usr/share/man/man5/.k5login.5.gz: gzip compressed data, max compression, from Unix, truncated
[12:57:28] Warning: Hidden file found: /usr/share/man/man5/.k5identity.5.gz: gzip compressed data, max compression, from Unix, truncat>

and i have problem with ufw ufw not starting at login

https://wiki.archlinux.org/title/Rkhunter

In the vein of false-positives I can at least tell you that I have all your listed files …

is exist something other for scan rootkit and other threaths? i use chkrootkit before on another system

Archwiki probably has decent recommendations…

https://wiki.archlinux.org/title/Security

https://wiki.archlinux.org/title/List_of_applications/Security

1 Like

I saw that warning, too. Near as I can tell (based on dates of previous log files), this popped up on an upgrade to mpd ((0.22.10-1 → 0.23-1, which added (for me) a ton of cruft.

Reboot your machine. I’ll bet it doesn’t show back up (unless you actively use JACK/JACK2, in which case you could make an exception to skip those).

<tl/dr>: Nothing to see here, move along.

1 Like