This is a rootkit written by a Dutch group called Tuxtendo. It was found in some infected Redhat 6.0/7.0 systems.

A complete analyse of Tuxkit, done by Spoonfork ( For more info, look at this analyse (author unknown): Analysis of a rootkit: Tuxkit



Entries to search on file “/etc/rc.d/rc.sysinit”:



All files with an “*” need to be search in all system

