[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Re:chkrootkit results on Raq4r



At 9:54 AM -0400 7/12/02, Goade, Matthew is rumored to have typed:

> Checking `lkm'... You have     5 process hidden for readdir command
> You have     6 process hidden for ps command
> Warning: Possible LKM Trojan installed

   Search the archives...this was just covered a few days ago. Short answer:
So long as you aren't seeing any other symptoms, and cannot replicate the
results (hint: run it manually), you are likely seeing the false positive
referenced directly on the chkrootkit main web page (hint: read through it).

         Charlie