Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Apr 2003
    Posts
    479

    Default hacked or false positives?

    Can someone please help me read the output from chkrootkit and Scan for Trojans? Thanks in advance!


    From chkrootkit:
    Checking `bindshell'... INFECTED (PORTS: 465)
    Checking `lkm'...
    You have 1 process hidden for readdir command
    You have 1 process hidden for ps command
    Warning: Possible LKM Trojan installed

    From WHM's Scan for Trojan Horses:
    Possible Trojan - /usr/bin/curl
    Possible Trojan - /usr/bin/podchecker
    Possible Trojan - /usr/bin/pstruct
    Possible Trojan - /usr/bin/splain
    Possible Trojan - /usr/bin/xsubpp
    Possible Trojan - /usr/bin/curl-config
    Possible Trojan - /usr/bin/dbiprof
    Possible Trojan - /usr/bin/sa-learn
    Possible Trojan - /usr/bin/spamassassin
    Possible Trojan - /usr/bin/spamc
    Possible Trojan - /usr/bin/spamd
    11 POSSIBLE Trojans Detected

  2. #2
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,313
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Most likely all false positives. Grab rkhunter and check the (more reliable) output from it.
    http://www.rootkit.nl/

  3. #3
    Member
    Join Date
    Jan 2005
    Posts
    34

    Default

    Just in case anyone reads this... I had the exact same problem from chkrootkit...

    I installed rkhunter and it was indeed a false positive...

    Install rkhunter it is alot cleaner and more accurate.

  4. #4
    Member
    Join Date
    Oct 2003
    Posts
    327

    Default

    And updated more often, which is important in such a tool.

    Don't forget to "show the love" to the author by buying him something on his Amazon wishlist. He's a good guy and very responsive.

Similar Threads & Tags
Similar threads

  1. New high rate of false positives in Mailscanner?
    By dory36 in forum cPanel Developers
    Replies: 5
    Last Post: 05-18-2007, 09:27 AM
  2. assp, mailscanner, ... false positives?
    By babakb in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-19-2007, 06:58 AM
  3. % of false positives for default spamassassin implementation?
    By spaceman in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-01-2006, 05:49 AM
  4. False Positives in "Quick Security" and "Trojan Horse" Scan
    By dwh2 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-29-2005, 03:52 PM
  5. anti-spam - is no 'false positives' achievable?
    By spaceman in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 01-18-2005, 12:10 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube