Displaying 1 result from an estimated 1 matches for "chkutmp".
2006 Dec 22
1
chkrootkit reporting possible LKM trojan
How can I be sure if it is LKM or not?
Today I've run chkrootkit and it gave me:
Checking `lkm'... You have 179 process hidden for readdir command
You have 179 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
Checking `chkutmp'... The tty of the following user process(es) were not found
in /var/run/utmp !
! RUID PID TTY CMD
! root 3206 tty1 /sbin/mingetty tty1
! root 3285 tty2 /sbin/mingetty tty2
! root 3337 tty3 /sbin/mingetty tty3
! root 3388 tty4 /sbin/mingetty...