Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 18 Feb 2007 23:04:18 +0900
From:      "FreeBSD MailingLists" <freebsd.ml@gmail.com>
To:        questions <freebsd-questions@freebsd.org>
Subject:   LKM Trojan?
Message-ID:  <ded8d7170702180604u53c748a1w7de5b01a29754c38@mail.gmail.com>

next in thread | raw e-mail | index | archive | help
When I run chkrootkit I get the following lines.

>Checking `lkm'... You have   107 process hidden for readdir command
>chkproc: Warning: Possible LKM Trojan installed

rkhunter doesn't seem to find anything.
I suspect that my machine might be compromised.
running "ls" in the /proc directory returns an empty list.
I have recompiled the kernel and world but the problem persists.
Any suggestions on how to fix this without having to reinstall from scratch?

TIA,
Tomoki



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?ded8d7170702180604u53c748a1w7de5b01a29754c38>