From owner-freebsd-questions@FreeBSD.ORG Sun Feb 18 14:04:19 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id E546916A401 for ; Sun, 18 Feb 2007 14:04:19 +0000 (UTC) (envelope-from freebsd.ml@gmail.com) Received: from wr-out-0506.google.com (wr-out-0506.google.com [64.233.184.235]) by mx1.freebsd.org (Postfix) with ESMTP id AD91B13C461 for ; Sun, 18 Feb 2007 14:04:19 +0000 (UTC) (envelope-from freebsd.ml@gmail.com) Received: by wr-out-0506.google.com with SMTP id i22so1328621wra for ; Sun, 18 Feb 2007 06:04:19 -0800 (PST) DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:mime-version:content-type; b=qNlEkruViBXwGdaOCDuTqd1M1CACYSq94bPF7Pb3j4G5ZRJ2NuSacVmSMoMeDogDhb5RAYMOMXGvRUN4C40Ng3Az+XlvNe8eLEF7AgAXFnCNku7c6sO3ypV5myBmAsm0Z3+IntJMx5sBui8M7+QAX7zOkVR0wUo/3Og3SfQfhgA= Received: by 10.114.111.1 with SMTP id j1mr2565585wac.1171807458175; Sun, 18 Feb 2007 06:04:18 -0800 (PST) Received: by 10.114.191.11 with HTTP; Sun, 18 Feb 2007 06:04:18 -0800 (PST) Message-ID: Date: Sun, 18 Feb 2007 23:04:18 +0900 From: "FreeBSD MailingLists" To: questions MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Subject: LKM Trojan? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 18 Feb 2007 14:04:20 -0000 When I run chkrootkit I get the following lines. >Checking `lkm'... You have 107 process hidden for readdir command >chkproc: Warning: Possible LKM Trojan installed rkhunter doesn't seem to find anything. I suspect that my machine might be compromised. running "ls" in the /proc directory returns an empty list. I have recompiled the kernel and world but the problem persists. Any suggestions on how to fix this without having to reinstall from scratch? TIA, Tomoki