-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hola: Si hago un "last -di" , me sale: peter pts/2 0.0.0.0 Thu Mar 17 23:26 still logged in peter pts/1 0.0.0.0 Thu Mar 17 23:24 still logged in peter pts/1 0.0.0.0 Thu Mar 17 23:08 - 23:09 (00:01) peter pts/1 0.0.0.0 Thu Mar 17 22:22 - 22:24 (00:02) peter pts/1 0.0.0.0 Thu Mar 17 22:20 - 22:21 (00:01) peter pts/1 0.0.0.0 Thu Mar 17 15:57 - 16:01 (00:03) peter pts/3 0.0.0.0 Thu Mar 17 15:20 - 15:56 (00:36) peter pts/1 0.0.0.0 Thu Mar 17 15:11 - 15:11 (00:00) peter pts/1 0.0.0.0 Thu Mar 17 11:12 - 11:12 (00:00) peter pts/0 0.0.0.0 Thu Mar 17 11:11 still logged in peter :0 220.138.236.183 Thu Mar 17 11:10 still logged in reboot system boot 0.0.0.0 Thu Mar 17 11:08 (12:22) peter pts/1 0.0.0.0 Thu Mar 17 02:25 - 02:26 (00:01) peter pts/3 0.0.0.0 Thu Mar 17 01:53 - 01:53 (00:00) peter pts/1 0.0.0.0 Wed Mar 16 20:26 - 20:26 (00:00) peter pts/1 0.0.0.0 Wed Mar 16 20:16 - 20:16 (00:00) peter pts/0 0.0.0.0 Wed Mar 16 20:16 - down (06:11) peter :0 220.138.236.183 Wed Mar 16 20:15 - 02:27 (06:11) peter pts/1 0.0.0.0 Wed Mar 16 19:30 - 19:30 (00:00) peter pts/0 0.0.0.0 Wed Mar 16 19:29 - 20:16 (00:46) peter :0 220.138.236.183 Wed Mar 16 19:29 - 20:14 (00:45) reboot system boot 0.0.0.0 Wed Mar 16 19:27 (06:59) peter pts/3 0.0.0.0 Wed Mar 16 17:29 - 17:31 (00:01) peter pts/3 0.0.0.0 Wed Mar 16 17:23 - 17:25 (00:01) peter pts/1 0.0.0.0 Wed Mar 16 17:06 - 17:06 (00:00) peter pts/0 0.0.0.0 Wed Mar 16 17:05 - 17:32 (00:27) peter :0 220.138.236.183 Wed Mar 16 17:05 - 17:32 (00:27) reboot system boot 0.0.0.0 Wed Mar 16 17:02 (00:30) peter pts/2 0.0.0.0 Wed Mar 16 12:03 - 12:05 (00:01) peter pts/2 0.0.0.0 Wed Mar 16 11:57 - 12:03 (00:05) peter pts/2 0.0.0.0 Wed Mar 16 10:53 - 11:13 (00:19) peter pts/3 0.0.0.0 Wed Mar 16 10:42 - 11:13 (00:30) peter pts/2 0.0.0.0 Wed Mar 16 10:27 - 10:53 (00:25) peter pts/2 0.0.0.0 Wed Mar 16 09:24 - 09:24 (00:00) peter pts/2 0.0.0.0 Wed Mar 16 09:00 - 09:00 (00:00) peter pts/1 0.0.0.0 Wed Mar 16 08:59 - down (08:02) peter :0 220.122.236.183 Wed Mar 16 08:58 - down (08:02) peter :0 220.122.236.183 Wed Mar 16 08:58 - 08:58 (00:00) reboot system boot 0.0.0.0 Wed Mar 16 08:56 (08:04) peter pts/2 0.0.0.0 Wed Mar 16 01:18 - 01:26 (00:08) peter pts/2 0.0.0.0 Wed Mar 16 00:59 - 01:03 (00:03) peter pts/2 0.0.0.0 Wed Mar 16 00:55 - 00:56 (00:00) peter pts/2 0.0.0.0 Tue Mar 15 22:49 - 22:50 (00:00) peter pts/2 0.0.0.0 Tue Mar 15 21:34 - 21:39 (00:05) peter pts/2 0.0.0.0 Tue Mar 15 21:16 - 21:24 (00:07) peter pts/2 0.0.0.0 Tue Mar 15 21:09 - 21:11 (00:02) peter pts/2 0.0.0.0 Tue Mar 15 21:07 - 21:07 (00:00) peter pts/2 0.0.0.0 Tue Mar 15 21:04 - 21:06 (00:01) peter pts/2 0.0.0.0 Tue Mar 15 20:17 - 20:18 (00:00) peter pts/4 0.0.0.0 Tue Mar 15 20:00 - 20:00 (00:00) peter pts/2 0.0.0.0 Tue Mar 15 19:58 - 20:04 (00:05) peter pts/4 0.0.0.0 Tue Mar 15 19:20 - 19:52 (00:31) peter pts/2 0.0.0.0 Tue Mar 15 18:34 - 19:07 (00:33) peter pts/2 0.0.0.0 Tue Mar 15 16:56 - 17:00 (00:04) peter pts/2 0.0.0.0 Tue Mar 15 12:29 - 12:29 (00:00) peter pts/1 0.0.0.0 Tue Mar 15 12:28 - down (13:03) peter :0 220.122.236.183 Tue Mar 15 12:27 - 01:31 (13:03) peter :0 220.122.236.183 Tue Mar 15 12:27 - 12:27 (00:00) reboot system boot 0.0.0.0 Tue Mar 15 12:21 (13:10) peter pts/2 0.0.0.0 Tue Mar 15 01:47 - 01:50 (00:03) peter pts/2 0.0.0.0 Mon Mar 14 21:46 - 21:46 (00:00) peter pts/2 0.0.0.0 Mon Mar 14 21:17 - 21:19 (00:01) peter pts/1 0.0.0.0 Mon Mar 14 21:15 - 01:58 (04:42) peter :0 220.122.236.183 Mon Mar 14 21:15 - 01:58 (04:42) peter :0 220.122.236.183 Mon Mar 14 21:15 - 21:15 (00:00) peter pts/2 0.0.0.0 Mon Mar 14 21:13 - 21:13 (00:00) peter pts/2 0.0.0.0 Mon Mar 14 20:25 - 20:39 (00:13) peter pts/2 0.0.0.0 Mon Mar 14 16:52 - 17:04 (00:12) peter pts/0 0.0.0.0 Mon Mar 14 16:30 - 16:41 (00:11) peter pts/5 0.0.0.0 Mon Mar 14 16:24 - 16:26 (00:01) peter pts/0 0.0.0.0 Mon Mar 14 13:03 - 13:09 (00:05) peter pts/0 0.0.0.0 Mon Mar 14 12:42 - 12:43 (00:01) peter pts/0 0.0.0.0 Mon Mar 14 12:35 - 12:37 (00:02) peter pts/0 0.0.0.0 Mon Mar 14 12:34 - 12:34 (00:00) peter pts/0 0.0.0.0 Mon Mar 14 12:33 - 12:34 (00:01) peter pts/0 0.0.0.0 Mon Mar 14 12:31 - 12:32 (00:00) peter pts/0 0.0.0.0 Mon Mar 14 12:28 - 12:29 (00:00) peter pts/0 0.0.0.0 Mon Mar 14 10:57 - 10:57 (00:00) peter pts/1 0.0.0.0 Mon Mar 14 10:53 - 21:15 (10:21) peter :0 220.138.236.183 Mon Mar 14 10:53 - 21:15 (10:22) peter :0 220.138.236.183 Mon Mar 14 10:53 - 10:53 (00:00) root tty1 0.0.0.0 Mon Mar 14 10:48 - 10:54 (00:06) peter :0 220.138.236.183 Mon Mar 14 10:47 - 10:47 (00:00) peter :0 220.138.236.183 Mon Mar 14 10:47 - 10:47 (00:00) peter :0 220.138.236.183 Mon Mar 14 10:45 - 10:46 (00:00) peter :0 220.138.236.183 Mon Mar 14 10:45 - 10:45 (00:00) reboot system boot 0.0.0.0 Mon Mar 14 10:42 (15:16) peter :0 220.138.3.64 Mon Mar 14 00:11 - 00:11 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:11 - 00:11 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:10 - 00:10 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:10 - 00:10 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:09 - 00:09 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:09 - 00:09 (00:00) root tty1 0.0.0.0 Mon Mar 14 00:08 - 00:09 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:06 - 00:08 (00:01) peter :0 220.138.3.64 Mon Mar 14 00:06 - 00:06 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:05 - 00:06 (00:00) peter :0 220.138.3.64 Mon Mar 14 00:05 - 00:05 (00:00) peter pts/1 0.0.0.0 Sun Mar 13 23:31 - 23:58 (00:26) peter pts/2 0.0.0.0 Sun Mar 13 23:04 - 23:22 (00:17) peter pts/2 0.0.0.0 Sun Mar 13 22:59 - 23:01 (00:01) peter pts/2 0.0.0.0 Sun Mar 13 22:55 - 22:55 (00:00) peter pts/1 0.0.0.0 Sun Mar 13 22:52 - 23:20 (00:28) peter pts/1 0.0.0.0 Sun Mar 13 22:39 - 22:48 (00:08) peter pts/1 0.0.0.0 Sun Mar 13 21:29 - 21:37 (00:07) peter pts/1 0.0.0.0 Sun Mar 13 21:26 - 21:26 (00:00) peter pts/1 0.0.0.0 Sun Mar 13 21:25 - 21:26 (00:00) peter pts/1 0.0.0.0 Sun Mar 13 21:21 - 21:24 (00:02) peter pts/1 0.0.0.0 Sun Mar 13 20:37 - 20:39 (00:01) peter pts/1 0.0.0.0 Sun Mar 13 20:12 - 20:29 (00:17) peter pts/1 0.0.0.0 Sun Mar 13 19:49 - 19:50 (00:01) peter pts/1 0.0.0.0 Sun Mar 13 19:48 - 19:48 (00:00) peter pts/0 0.0.0.0 Sun Mar 13 19:45 - down (04:26) peter :0 220.138.3.64 Sun Mar 13 19:44 - 00:04 (04:19) peter :0 220.138.3.64 Sun Mar 13 19:44 - 19:44 (00:00) peter tty2 0.0.0.0 Sun Mar 13 19:13 - 19:19 (00:06) peter tty1 0.0.0.0 Sun Mar 13 18:59 - 19:48 (00:49) reboot system boot 0.0.0.0 Sun Mar 13 18:56 (05:14) peter pts/4 0.0.0.0 Sun Mar 13 18:50 - 18:51 (00:01) peter pts/4 0.0.0.0 Sun Mar 13 17:26 - 17:26 (00:00) peter :0 248.112.3.64 Sat Mar 12 12:15 - down (1+06:39) peter :0 248.112.3.64 Sat Mar 12 12:15 - 12:15 (00:00) reboot system boot 0.0.0.0 Sat Mar 12 12:14 (1+06:40) peter :0 248.112.3.64 Fri Mar 11 05:02 - 05:53 (1+00:51) peter :0 248.112.3.64 Fri Mar 11 05:02 - 05:02 (00:00) reboot system boot 0.0.0.0 Fri Mar 11 05:00 (1+00:54) peter :0 248.112.3.64 Thu Mar 10 10:32 - 01:37 (15:05) peter :0 248.112.3.64 Thu Mar 10 10:32 - 10:32 (00:00) reboot system boot 0.0.0.0 Thu Mar 10 10:30 (15:08) peter :0 248.112.3.64 Wed Mar 9 14:53 - 02:32 (11:39) peter :0 248.112.3.64 Wed Mar 9 14:53 - 14:53 (00:00) peter pts/2 0.0.0.0 Wed Mar 9 13:09 - 13:12 (00:03) peter pts/2 0.0.0.0 Wed Mar 9 13:03 - 13:04 (00:00) peter :0 248.112.3.64 Wed Mar 9 11:37 - 14:52 (03:15) peter :0 248.112.3.64 Wed Mar 9 11:37 - 11:37 (00:00) reboot system boot 0.0.0.0 Wed Mar 9 11:34 (14:58) peter :0 248.112.3.64 Wed Mar 9 08:03 - 08:43 (00:39) peter :0 248.112.3.64 Wed Mar 9 08:03 - 08:03 (00:00) reboot system boot 0.0.0.0 Wed Mar 9 08:02 (00:41) peter :0 248.112.3.64 Tue Mar 8 19:10 - 02:20 (07:10) peter :0 248.112.3.64 Tue Mar 8 19:10 - 19:10 (00:00) reboot system boot 0.0.0.0 Tue Mar 8 19:03 (07:16) peter :0 248.112.3.64 Tue Mar 8 14:18 - 18:14 (03:55) peter :0 248.112.3.64 Tue Mar 8 14:18 - 14:18 (00:00) reboot system boot 0.0.0.0 Tue Mar 8 14:07 (04:07) peter :0 248.112.3.64 Tue Mar 8 00:28 - 03:09 (02:40) peter :0 248.112.3.64 Tue Mar 8 00:28 - 00:28 (00:00) reboot system boot 0.0.0.0 Tue Mar 8 00:26 (02:42) peter :0 248.112.3.64 Mon Mar 7 22:10 - crash (02:15) peter :0 248.112.3.64 Mon Mar 7 22:10 - 22:10 (00:00) peter :0 248.112.3.64 Mon Mar 7 22:09 - 22:10 (00:00) peter :0 248.112.3.64 Mon Mar 7 22:09 - 22:09 (00:00) peter :0 248.112.3.64 Mon Mar 7 22:05 - 22:09 (00:04) peter :0 248.112.3.64 Mon Mar 7 22:05 - 22:05 (00:00) peter :0 248.112.3.64 Mon Mar 7 22:04 - 22:04 (00:00) peter :0 248.112.3.64 Mon Mar 7 22:04 - 22:04 (00:00) peter pts/1 0.0.0.0 Mon Mar 7 21:56 - 22:03 (00:07) peter :0 248.112.3.64 Mon Mar 7 21:56 - 22:03 (00:07) peter :0 248.112.3.64 Mon Mar 7 21:56 - 21:56 (00:00) peter :0 248.112.3.64 Mon Mar 7 21:54 - 21:55 (00:00) peter :0 248.112.3.64 Mon Mar 7 21:54 - 21:54 (00:00) peter tty1 0.0.0.0 Mon Mar 7 21:53 - 21:54 (00:00) peter :0 248.112.3.64 Mon Mar 7 21:53 - 21:54 (00:01) peter :0 248.112.3.64 Mon Mar 7 21:53 - 21:53 (00:00) reboot system boot 0.0.0.0 Mon Mar 7 21:51 (05:18) peter tty1 0.0.0.0 Mon Mar 7 21:28 - down (00:21) peter pts/1 0.0.0.0 Mon Mar 7 21:27 - down (00:22) peter :0 248.112.3.64 Mon Mar 7 21:27 - down (00:22) peter :0 248.112.3.64 Mon Mar 7 21:27 - 21:27 (00:00) reboot system boot 0.0.0.0 Mon Mar 7 21:25 (00:24) root :0 248.112.3.64 Mon Mar 7 20:11 - 20:56 (00:44) root :0 248.112.3.64 Mon Mar 7 20:11 - 20:11 (00:00) root :0 248.112.3.64 Mon Mar 7 20:10 - 20:11 (00:00) root :0 248.112.3.64 Mon Mar 7 20:10 - 20:10 (00:00) peter :0 248.112.3.64 Mon Mar 7 20:09 - 20:10 (00:00) peter :0 248.112.3.64 Mon Mar 7 20:09 - 20:09 (00:00) root :0 248.112.3.64 Mon Mar 7 20:01 - 20:07 (00:06) root :0 248.112.3.64 Mon Mar 7 20:01 - 20:01 (00:00) peter :0 248.112.3.64 Mon Mar 7 20:00 - 20:00 (00:00) peter :0 248.112.3.64 Mon Mar 7 20:00 - 20:00 (00:00) peter pts/1 0.0.0.0 Mon Mar 7 19:58 - down (00:58) peter :0 248.112.3.64 Mon Mar 7 19:58 - 19:59 (00:01) peter :0 248.112.3.64 Mon Mar 7 19:58 - 19:58 (00:00) peter :0 248.112.3.64 Mon Mar 7 19:56 - 19:56 (00:00) peter :0 248.112.3.64 Mon Mar 7 19:56 - 19:56 (00:00) peter tty1 0.0.0.0 Mon Mar 7 19:51 - down (01:05) root :0 248.112.3.64 Mon Mar 7 19:50 - 19:51 (00:01) root :0 248.112.3.64 Mon Mar 7 19:50 - 19:50 (00:00) peter :0 248.112.3.64 Mon Mar 7 19:49 - 19:50 (00:00) peter :0 248.112.3.64 Mon Mar 7 19:49 - 19:49 (00:00) reboot system boot 0.0.0.0 Mon Mar 7 19:48 (01:09) peter pts/71 0.0.0.0 Mon Mar 7 19:40 - 19:40 (00:00) peter pts/69 0.0.0.0 Mon Mar 7 19:28 - 19:42 (00:14) peter pts/67 0.0.0.0 Mon Mar 7 17:15 - down (02:31) peter pts/65 0.0.0.0 Mon Mar 7 16:56 - 16:58 (00:01) peter pts/64 0.0.0.0 Mon Mar 7 16:54 - 17:11 (00:16) peter pts/63 0.0.0.0 Mon Mar 7 16:20 - 16:21 (00:01) peter pts/62 0.0.0.0 Mon Mar 7 16:18 - 16:19 (00:01) peter pts/52 0.0.0.0 Mon Mar 7 14:59 - 15:30 (00:30) peter pts/49 0.0.0.0 Mon Mar 7 14:34 - 14:34 (00:00) peter pts/47 0.0.0.0 Mon Mar 7 14:15 - 14:16 (00:01) peter pts/45 0.0.0.0 Mon Mar 7 12:57 - 13:01 (00:03) peter pts/44 0.0.0.0 Mon Mar 7 12:48 - 14:59 (02:10) peter pts/43 0.0.0.0 Mon Mar 7 12:42 - 12:42 (00:00) peter :0 248.112.3.64 Mon Mar 7 12:37 - 19:42 (07:05) peter :0 248.112.3.64 Mon Mar 7 12:37 - 12:37 (00:00) reboot system boot 0.0.0.0 Mon Mar 7 12:36 (07:10) y mirando con "whois IP" me salen conexiones a Taiwan...salvo con la correspondiente 248.112.3.64 que dice: "No whois server is known for this kind of object." La pregunta es: Suponiendo que la IP 248.112.3.64 sea de uso interno de mi entorno de ventanas (KDE) y que por eso no tiene respuesta whois...¿Quien o quienes son las otras que me dicen que son de Tw? Ni chkrootkit ni rkhunter me encuentran nada extraño y mi antivirus (Clamav / Klamav) tampoco. Agradeceria cualquier respuesta. Un saludo Peter Holm. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iQIVAwUBQjoGaS+g7+3ZFf1AAQKWgA/+M4zEKtLHclPpwco+zCMFMVrW6qxJS7wE 3dQbOpZo2uPjcYg8zT+IPkjGhNX13UxCRrJ62vGGL/KjUaCrWSbL6OzHk4S3tVxa kun/43GU79iCKosymYgHQfBK4LRbxmEWLUKp1GelJq6W3+4m6+1aqFOmENPj49IB jghBlRaZfMPXMOngzwmjRU9GwBfL94Pp+xM9xQ4qNv7chrNMuXQWIHD6qznXJB4o cP/9uW8dFcvRd135X4XfJtp8YhbDtVDRItwrLdqkLw1qN078349xbpVJDR8x0yge 1pRmV42SI2HWMVYQkejc8TTRL+9zciQdTQ/y4/Qrx69QMpBvmRNOW3rQ+vbxKnZn nW8WRm/lo9kaw3zc1WCgskZHNQ366rEXGCiM+4uz0lVyk6OxNLbxZXLROdcFnNyD rOBHf8DD5vsWnyZ1cv7I4nhz6/fl0KPji0S5wMYBBPtpPDBHZFsZNvp99A7Y7oJG sEEQakZpvjwqyYQAOHPMkB6/QCRZDOizINwR3cags8lAgZNKVsqaxKczQL25iQ9n GNtNhyxgkmRRGHtSjIXb5/19CX6/m6YKQSQ09YqVetwEc+spthRo46KIrk70HyB9 1vEZqjp28FVzC6FVZds75X0JxjOi/yEjxP0SqK6oj/tGHkACxEdona2MIV6V8gqH juWZAZMavJM= =lbm+ -----END PGP SIGNATURE-----