Re: LKM Trojan installed

From: Bruce Garlock (bruceg@garlockprinting.com)
Date: 02/08/03

  • Next message: Nathan Yocom: "Re: LKM Trojan installed"
    Date: Fri, 07 Feb 2003 21:51:22 -0500
    From: Bruce Garlock <bruceg@garlockprinting.com>
    To: "Rivanor P. Soares" <rivanor@bol.com.br>
    
    

    Rivanor P. Soares wrote:

    > While running 'chkrootkit' at my box (RH 7.3) I saw the following:
    >
    > Checking `lkm'... You have 69 process hidden for ps command
    > Warning: Possible LKM Trojan installed
    >
    > Could this be *true* ? How can I discover it?
    >
    > Cheers...
    >
    > Rivanor.

    Make sure you are running chkrootkit 0.39, as there are fixes in
    chkproc.c I had some problems with version 0.38, and when I tried 0.37,
    I didn't get the 'xx process hidden for ps command', and the warning.
     Updating to 0.39 showed no warnings either. If you are running 0.39,
    please follow the advise of the other posts. My guess is that 0.38 has
    a bug, with chkproc, but you can always contatct the author to verify.

    HTH...

    Bruce



    Relevant Pages

    • Re: LKM Trojan installed
      ... On Fri, 07 Feb 2003, Rivanor P. Soares wrote: ... You have 69 process hidden for ps command ... Warning: Possible LKM Trojan installed ...
      (Focus-Linux)
    • Re: LKM Trojan installed
      ... You have 54 process hidden for ps command ... > Warning: Possible LKM Trojan installed ... > 3) Seeing process: ... a couple finished between running chkrootkit and ps). ...
      (Focus-Linux)
    • LKM Trojan installed
      ... While running 'chkrootkit' at my box I saw the following: ... You have 69 process hidden for ps command ... Warning: Possible LKM Trojan installed ... Rivanor. ...
      (Focus-Linux)
    • Re: "file locked by another user" mystery
      ... cannot have a previous ON WARNING command and expect it to work. ... ON WARNING THEN CONTINUE or an ON ERROR THEN GOTO EXIT. ... $ SH SYM $SEVERITY ...
      (comp.os.vms)
    • Re: "file locked by another user" mystery
      ... in the DCL Help that if you have an ON SEVERE command that you ... cannot have a previous ON WARNING command and expect it to work. ... Specifies either the severity level of an error or a Ctrl/Y ...
      (comp.os.vms)