Re: LKM Trojan installed

From: Chris Rouch (cdvr@pobox.com)
Date: 02/19/03

  • Next message: Felix Cuello: "entropy + openSSL question"
    From: Chris Rouch <cdvr@pobox.com>
    To: "Rivanor P. Soares" <rivanor@bol.com.br>
    Date: 19 Feb 2003 14:03:10 +0100
    
    

    > 2) While I was running chkrootkit-0.39a:
    > Checking `ps'... not infected
    > ...
    > Checking `lkm'... You have 54 process hidden for ps command
    > Warning: Possible LKM Trojan installed
    > --
    >
    > 3) Seeing process:
    > [root@localhost chkrootkit-0.39a]# ps ax
    > PID TTY STAT TIME COMMAND
    > 1 ? S 0:04 init [3]
    > 2 ? SW 0:00 [keventd]
    > ...
    > 4881 pts/0 S 0:00 bash
    > 4917 pts/0 S 0:00 vim rootkit
    > 4918 pts/1 R 0:00 ps ax
    > Total: 52
    > At /proc : 52 process, too
    > --

    chkrootkit seems to think that *all* your processes are hidden (assuming
    a couple finished between running chkrootkit and ps).

    I suspect that the ps is being run with the wrong arguments (or the
    wrong ps is being run). Have a look at chkproc.c and make sure that the
    definition of PS is the one you want for your system.

    Regards,

    Chris



    Relevant Pages

    • Re: LKM Trojan installed
      ... Rivanor P. Soares wrote: ... Make sure you are running chkrootkit 0.39, ... I didn't get the 'xx process hidden for ps command', and the warning. ...
      (Focus-Linux)
    • Re: "file locked by another user" mystery
      ... cannot have a previous ON WARNING command and expect it to work. ... ON WARNING THEN CONTINUE or an ON ERROR THEN GOTO EXIT. ... $ SH SYM $SEVERITY ...
      (comp.os.vms)
    • Re: "file locked by another user" mystery
      ... in the DCL Help that if you have an ON SEVERE command that you ... cannot have a previous ON WARNING command and expect it to work. ... Specifies either the severity level of an error or a Ctrl/Y ...
      (comp.os.vms)
    • Re: "file locked by another user" mystery
      ... cannot have a previous ON WARNING command and expect it to work. ... and ON ERROR command, execution would simply continue. ... When a severe error occurs, ...
      (comp.os.vms)
    • SUMMARY: Problems bringing up domains in a E10000 - Panic Boot
      ... Command is respawning too rapidly. ... WARNING: forceload of misc/md_trans failed ... > panic - boot: Could not mount filesystem. ...
      (SunManagers)