[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] chkrootkit-0.38/RaQ4



"B. Runge" <brunge@xxxxxxxxxxx> wrote:
> Checking `lkm'... You have     2 process hidden for readdir command
> You have     2 process hidden for ps command
> Warning: Possible LKM Trojan installed

Definitely a bad sign.  It could be a false positive so run several times
over a few minute period and if it's reported all times then it's likely the
result of a trojan.  I'd also run lsof to see what's running and
netstat -tupan to check for open ports and verify binaries like ps, ls,
netstat, kill, md5sum, etc. by doing an md5sum and comparing to known clean
binaries.  You can grab them from the Cobalt FTP site.

--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/