[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-developers] What do I have to do??



At 09:53 AM 8/17/2003 +0200, you wrote:
I one log of chrootkit I found this:

Checking `lkm'... You have     1 process hidden for readdir command
You have     1 process hidden for ps command
Warning: Possible LKM Trojan installed

What do I have to do to remove this Trojan?

Thank you,

Rolf Berkenbosch

Hello Rolf,

It is common and frequent to get these sort of false positives. First, login to the machine ona terminal and re-run chkrootkit manually. If you get another positive, wait and run again. Finally, should you still show positives, you should research what to look for on the corrupted system.

It is most likely nothing to worry about.

Cheers!