Abdul-Rashid Abdullah wrote:
> Aloha,
>
> I had the following output from my rookit check. What should be the most
> appropriate steps to take to tackle this?
>
> Checking `lkm'... You have 1 process hidden for readdir command
> You have 1 process hidden for ps command
> Warning: Possible LKM Trojan installed
This is the most common false positive from chkrootkit in my experience. Run
chkrootkit a few more times when the box isn't busy and see if it goes away. If
it does, you've got nothing to worry about.
Brian