Possible LKM Trojan , Need Help

From: Thomas H. George (xyz_at_spininternet.com)
Date: 11/29/03

  • Next message: Karsten M. Self: "Re: How to get away with small /var partition"
    Date: Sat, 29 Nov 2003 05:49:31 -0500
    To: debian-user@lists.debian.org
    
    

    chkrootkit reported possible LKM Trojan. 4 processes hidden for ps command.

    Before reformating the hard drive and reinstalling Debian, started a dvd
    backup using growisofs.
    The backup of /usr was successful, backup of /var failed with duplicate
    names in /rr_moved.

    Obviously I would like to delete /rr_moved but it is hidden from me. Is
    there any way to do this?

    In the mean time I am continuing the backup on the assumption that I
    might retrieve specific files without reconatiminating the system.

    The backup of /home was successful with the warning "missing whole name
    for 'rr_moved'"

    Tom

    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Karsten M. Self: "Re: How to get away with small /var partition"

    Relevant Pages