Checking `lkm'... You have 4 process hidden for readdir command You have 1 process hidden for ps command chkproc: Warning: Possible LKM Trojan installed
[root@ns16 chkrootkit-0.49]# ./chkproc -v PID 2912(/proc/2912): not in readdir output PID 2912: not in ps output PID 3046(/proc/3046): not in readdir output PID 3046: not in ps output PID 3047(/proc/3047): not in readdir output PID 3047: not in ps output PID 3048(/proc/3048): not in readdir output PID 3048: not in ps output PID 3049(/proc/3049): not in readdir output PID 3049: not in ps output PID 3571(/proc/3571): not in readdir output PID 3571: not in ps output PID 3572(/proc/3572): not in readdir output PID 3572: not in ps output PID 3674(/proc/3674): not in readdir output PID 3674: not in ps output PID 3693(/proc/3693): not in readdir output PID 3693: not in ps output PID 7076(/proc/7076): not in getpriority readdir output PID 21672(/proc/21672): not in readdir output PID 21672: not in ps output PID 21676(/proc/21676): not in getpriority readdir output PID 21677(/proc/21677): not in getpriority readdir output You have 13 process hidden for readdir command You have 10 process hidden for ps command [root@ns16 chkrootkit-0.49]#
[root@ns16 chkrootkit-0.49]# ./chkproc -v PID 2912(/proc/2912): not in readdir output PID 2912: not in ps output PID 21440(/proc/21440): not in readdir output PID 21440: not in ps output PID 21441(/proc/21441): not in readdir output PID 21441: not in ps output You have 3 process hidden for readdir command You have 3 process hidden for ps command [root@ns16 chkrootkit-0.49]# [root@ns16 chkrootkit-0.49]# [root@ns16 chkrootkit-0.49]# [root@ns16 chkrootkit-0.49]# cd /proc21441/ && cat cmdline -bash: cd: /proc21441/: No such file or directory [root@ns16 chkrootkit-0.49]# cd /proc21440/ && cat cmdline -bash: cd: /proc21440/: No such file or directory [root@ns16 chkrootkit-0.49]# cd /proc/21440/ && cat cmdline /var/lib/nfs/statd/dm/libijs.so211.239.155.925 der by [root@ns16 21440]# kill 21440 [root@ns16 21440]# kill 21440 -bash: kill: (21440) - No such process
cd /proc/1250/ && cat cmdline
File properties checks... Required commands check failed Files checked: 128 Suspect files: 6
Rootkit checks... Rootkits checked : 254 Possible rootkits: 1 Rootkit names : Xzibit Rootkit
Applications checks... Applications checked: 6 Suspect applications: 4
The system checks took: 7 minutes and 58 seconds
All results have been written to the log file (/var/log/rkhunter.log)
One or more warnings have been found while checking the system. Please check the log file (/var/log/rkhunter.log)
|