Results 1 to 3 of 3

Thread: Chkrootkit findings and where is the Chkrootkit log??

  1. #1
    Join Date
    Jun 2010
    Beans
    1

    Exclamation Chkrootkit findings and where is the Chkrootkit log??

    I did a simple chkrootkit in gnome-terminal (10.04) and everything checked out fine except these lines,

    Code:
    Checking `lkm'...                                           You have     2 process hidden for readdir command
    You have     3 process hidden for ps command
    chkproc: Warning: Possible LKM Trojan installed
    I cant find out what the processes are because there is not chkrootkit log and there is nothing in "/var/log/chkrootkit". No hidden files, nothing.

    Thank you for reading my post. Any help will be appreciated.

  2. #2
    Join Date
    Mar 2006
    Location
    Williams Lake
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: Chkrootkit findings and where is the Chkrootkit log??

    It is more than likely a false positive, doing a quick search on your error, shows pages and pages of the same thing. Is there are reason you ran chkrootkit? Is this a fresh install?

    In most cases these are pretty poor tools, as they only alert you after the fact.

    I would suggest you read the stickies at the top of the page, if you want to learn about securing your system.

  3. #3
    Join Date
    Mar 2010
    Location
    /home
    Beans
    9,753
    Distro
    Xubuntu

    Re: Chkrootkit findings and where is the Chkrootkit log??

    See here:

    http://ubuntuforums.org/showpost.php...39&postcount=7

    and here:

    http://ubuntuforums.org/showthread.php?t=510812

    and here:

    http://www.togaware.com/linux/surviv..._Security.html

    As cariboo907 already said, these are in all likelihood false positives.
    Last edited by Rubi1200; June 19th, 2010 at 09:35 PM.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •