[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Possible LKM Trojan , Need Help



chkrootkit reported possible LKM Trojan.  4 processes hidden for ps command.

Before reformating the hard drive and reinstalling Debian, started a dvd backup using growisofs. The backup of /usr was successful, backup of /var failed with duplicate names in /rr_moved.

Obviously I would like to delete /rr_moved but it is hidden from me. Is there any way to do this?

In the mean time I am continuing the backup on the assumption that I might retrieve specific files without reconatiminating the system.

The backup of /home was successful with the warning "missing whole name for 'rr_moved'"

Tom




Reply to: