This rkhunter software is driving me nuts with all these false positive alerts.
ALLOWHIDDENFILE apparently is not working on symbolic links (version 1.3.8) and I was unable to whitelist this “/dev/.initramfs” file until I found this blog below:
http://digitalcardboard.com/blog/2012/05/24/ubuntu-12-04-rkhunter-1-3-8-false-positives/
Follow the steps that the blogger mentioned above and you will be able to whitelist symbolic links
rkhunter manual
http://rkhunter.sourceforge.net/
Other links:
http://ycsoftware.net/please-inspect-this-machine-because-it-may-be-infectedrkhunter/