Re: LKM Trojan (david walcroft)

From: Philippe Lasfargues (philippe.lasfargues_at_tele2.fr)
Date: 12/01/04

  • Next message: Dave Roberts: "Re: Nautilus behavior"
    To: fedora-list@redhat.com
    Date: Wed, 01 Dec 2004 07:53:13 +0100
    
    

    ------------------------------

    Message: 16
    Date: Wed, 01 Dec 2004 10:05:14 +1000
    From: david walcroft <david_walcroft@yahoo.com.au>
    Subject: LKM Trojan
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    Message-ID: <41AD0ABA.2010705@yahoo.com.au>
    Content-Type: text/plain; charset=ISO-8859-1; format=flowed

    Hi,
         yesterday chkrootkit logged this

    Checking `lkm'...
      You have 2 process hidden for readdir command
    You have 2 process hidden for ps command
    Warning: Possible LKM Trojan installed

    Today it logs

    Checking `lkm'...
    You have 4 process hidden for readdir command
    You have 4 process hidden for ps command
    Warning: Possible LKM Trojan installed

    Would these be a 'false positive' or for real and if so how do I
    confirm and remove any infected process/trojan

       Thanks david

    ------------------------------

    Hi David,

    Sometimes I have 64 process hidden for readdir command... with chkrootkit.
    But nothing wrong with Rootkit Hunter 1.1.8. (http://www.rootkit.nl/)

    Please try it and tell me.

    Philippe

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Dave Roberts: "Re: Nautilus behavior"

    Relevant Pages

    • Re: chkroot warning
      ... rsina wrote: ... > You have 11 process hidden for ps command ... > Warning: Possible LKM Trojan installed ... This is from the Mandrake list, but it also pertains to the lkm trojan, ...
      (comp.os.linux.security)
    • lkm trojan
      ... I just ran chkrootkit on one of my machines at it turned up the ... You have 4 process hidden for ps command ... Warning: Possible LKM Trojan installed ... How do I diagnose this further, and if there is an LKM trojan, how do I ...
      (Debian-User)
    • Re: More died on open command (from 55103)
      ... I'm working with Activestate Activeperl 5.6 on a Windows ... >left of the readdir command. ... >processing block to the left of the readdir command. ... I have used similar to process directories of EDI translated data; ...
      (perl.beginners)
    • Re: chkrootkit and vncserver
      ... > This morning's normal system checks triggered alarms. ... > You have 5 process hidden for ps command ... > Warning: Possible LKM Trojan installed ...
      (Fedora)
    • Re: [SLE] Re: [suse-security] chkrootkit vs. 9.1 professional?
      ... On Wednesday 18 August 2004 04:05, Scott Leighton wrote: ... > You have 7 process hidden for readdir command ... > Warning: Possible LKM Trojan installed ...
      (SuSE)