VMware Communities
Richard1907
Contributor
Contributor

is this a false positive

can  anyone  tell  me  if  this  safe  or  not 

ran rkhunter  --propupd  and  update  then   -c    and  this  poped  up   

'/tmp/vmware-root/usbarb-3398.log' (score: 350) contains some suspicious content and should be checked.
my  system  is  an  aptosid    xfce  32  bit   
i  have  the  latest  vmware  installed   
0 Kudos
3 Replies
a_p_
Leadership
Leadership

I can't tell you for sure without seing the file. However, the log file is usually a plain text file and therefore I'm almost sure this is false positive.

André

Richard1907
Contributor
Contributor

thanks    here  is  log    file    as  you  said  its  plain  text     

Sep 11 08:27:27.038: usbArb| Log for VMware USB Arbitration Service pid=3398 ve

rsion=3.1.4 build=build-385536 option=Release

Sep 11 08:27:27.038: usbArb| The process is 32-bit.

Sep 11 08:27:27.038: usbArb| Host codepage=UTF-8 encoding=UTF-8

Sep 11 08:27:27.038: usbArb| DICT --- USER PREFERENCES

Sep 11 08:27:27.038: usbArb| DICT --- USER DEFAULTS //.vmware/config

Sep 11 08:27:27.038: usbArb| DICT --- HOST DEFAULTS /etc/vmware/config

Sep 11 08:27:27.038: usbArb| DICT                NETWORKING = yes

Sep 11 08:27:27.038: usbArb| DICT installerDefaults.dataCollectionEnabled = yes

Sep 11 08:27:27.038: usbArb| DICT            VMBLOCK_CONFED = yes

Sep 11 08:27:27.038: usbArb| DICT           gksu.rootMethod = sudo

Sep 11 08:27:27.038: usbArb| DICT                    libdir = /usr/lib/vmware

Sep 11 08:27:27.038: usbArb| DICT               VMCI_CONFED = yes

Sep 11 08:27:27.038: usbArb| DICT        vix.config.version = 1

Sep 11 08:27:27.038: usbArb| DICT              VSOCK_CONFED = yes

Sep 11 08:27:27.038: usbArb| DICT             initscriptdir = /etc/init.d

Sep 11 08:27:27.038: usbArb| DICT installerDefaults.componentDownloadEnabled =

yes

Sep 11 08:27:27.038: usbArb| DICT    player.product.version = 3.1.4

Sep 11 08:27:27.038: usbArb| DICT installerDefaults.transferVersion = 1

Sep 11 08:27:27.038: usbArb| DICT installerDefaults.autoSoftwareUpdateEnabled =

yes

Sep 11 08:27:27.038: usbArb| DICT            authd.fullpath = /usr/sbin/vmware-

authd

Sep 11 08:27:27.038: usbArb| DICT                    bindir = /usr/bin

Sep 11 08:27:27.038: usbArb| DICT       product.buildNumber = 385536

Sep 11 08:27:27.038: usbArb| DICT --- SITE DEFAULTS /usr/lib/vmware/config

Sep 11 08:27:27.039: usbArb| DICT                  tag.help = introduction.htm

Sep 11 08:27:27.039: usbArb| DICT   tag.configurationEditor = config_editor_newvm.htm

Sep 11 08:27:27.039: usbArb| DICT             tag.ideConfig = devices_virtualdrive.htm

:Sep 11 08:27:27.039: usbArb| DICT          tag.floppyConfig = devices_floppy.htm

Sep 11 08:27:27.039: usbArb| DICT           tag.mouseConfig = devices_mouse.htm

Sep 11 08:27:27.039: usbArb| DICT             tag.netConfig = devices_netadapter.htm

Sep 11 08:27:27.039: usbArb| DICT        tag.parallelConfig = devices_parallel.htm

Sep 11 08:27:27.039: usbArb| DICT          tag.serialConfig = devices_serial.htm

Sep 11 08:27:27.039: usbArb| DICT           tag.soundConfig = devices_sound.htm

Sep 11 08:27:27.039: usbArb| DICT             tag.memConfig = configvm_memory.htm

Sep 11 08:27:27.039: usbArb| DICT            tag.miscConfig = configvm.htm

Sep 11 08:27:27.039: usbArb| DICT             tag.usbConfig = devices_usb.htm

Sep 11 08:27:27.039: usbArb| DICT         tag.displayConfig = configvm_display-problems.htm

Sep 11 08:27:27.039: usbArb| DICT                 tag.tools = vmtools.htm

Sep 11 08:27:27.039: usbArb| USB: Unable to open "/proc/bus/usb/devices" (No such file or directory).

Sep 11 08:27:27.039: usbArb| USBGL: USB Sysfs found at /dev/bus/usb

Sep 11 08:27:27.040: usbArb| USBArb: 2 Devices enumerated

Sep 11 08:27:27.040: usbArb| USBArb: Device 0:name:Ricoh\ Integrated\ Webcam vid:05ca pid:180a path:1/6 speed:high family:other,video id:1000305ca180a owner:(null)

Sep 11 08:27:27.040: usbArb| USBArb: Device 1:name:Microsoft\ USB\ camera vid:045e pid:00f5 path:6/1 speed:full family:vendor,audio id:60002045e00f5 owner:(null)

0 Kudos
a_p_
Leadership
Leadership

I'm not too deep into Linux. However, if it does not allow ADS (Alternate Data Streams) like Windows I would consider this to be a false positive. To get rid of the warning, I would just delete the log file.

André

0 Kudos