Re: LKM Trojan installed

From: Cal Peake (
Date: 02/08/03

    Date: Fri, 7 Feb 2003 19:27:23 -0500 (EST)
    From: Cal Peake <>
    To: "Rivanor P. Soares" <>

    > While running 'chkrootkit' at my box (RH 7.3) I saw the following:
    > Checking `lkm'... You have 69 process hidden for ps command
    > Warning: Possible LKM Trojan installed
    > Could this be *true* ? How can I discover it?


    I know that RH patches their ps command to hide threads. If you're running
    a multi-threaded process (such as coldfusion) it very well could be why
    you're getting this warning.


