Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Apr 2004
    Posts
    9

    Default HELP,HELP Trojan Horses Detected by (WHM)

    Hidden Pid detected! [pid 143]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/sbin/adjkerntz]

    Hidden Pid detected! [pid 266]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/sbin/syslogd]

    Hidden Pid detected! [pid 359]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/sbin/usbd]

    Hidden Pid detected! [pid 408]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/sbin/sshd]

    Hidden Pid detected! [pid 426]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/sbin/cron]

    Hidden Pid detected! [pid 446]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/sbin/named]

    Hidden Pid detected! [pid 474]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/local/bin/perl]

    Hidden Pid detected! [pid 479]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/local/libexec/proftpd]

    Hidden Pid detected! [pid 584]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/local/cpanel/3rdparty/bin/melange]

    Hidden Pid detected! [pid 595]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/bin/sh]

    Hidden Pid detected! [pid 636]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/libexec/getty]

    Hidden Pid detected! [pid 637]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/libexec/getty]

    Hidden Pid detected! [pid 638]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/libexec/getty]

    Hidden Pid detected! [pid 639]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/libexec/getty]

    Hidden Pid detected! [pid 640]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/libexec/getty]




    I use freebsd ,Please tell me how to do next?

    help,help!!

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    May 2002
    Posts
    122

    Default

    Based on the processes listed, I am guessing this is a FreeBSD box. I have seen a similar occurance on FreeBSD, they are false positives.

  3. #3
    Member
    Join Date
    Apr 2004
    Posts
    9

    Default

    Please tell me what to do next ?
    Do i need rebuild my freebsd system or only kernal?

  4. #4
    Member nyjimbo's Avatar
    Join Date
    Jan 2003
    Location
    New York
    Posts
    1,105

    Default

    I've never seen this sort of thing. How is it that WHM alerted you to it, did you run something ??.
    "A dog has raised it’s hind leg on the age of nevermore !"
    -- Rolf

  5. #5
    Member
    Join Date
    Apr 2004
    Posts
    9

    Default

    I run nothing.

  6. #6
    Member
    Join Date
    Apr 2004
    Posts
    9

    Default

    Please tell me how to solve it!!


  7. #7
    Member nyjimbo's Avatar
    Join Date
    Jan 2003
    Location
    New York
    Posts
    1,105

    Default

    Do you have console access, can you run a "ps ax" and see if those are normal tasks.

    Since the thing is giving you the PIDs, if you do a "ps ax" and see those pids and they show the programs as listed in the warning then they cant be hidden from ps and then all you have to do is go see some of the date stamps of those files, if they match the rest of most of the binaries chances are you are seeing a false positive as the other poster mentioned.
    "A dog has raised it’s hind leg on the age of nevermore !"
    -- Rolf

  8. #8
    Member
    Join Date
    Apr 2004
    Posts
    9

    Default

    I run chkrootkit ,found 17 process hidden form ps
    ,and also warn my server mey have rootkit.

Similar Threads & Tags
Similar threads

  1. 'Trojan Horses Detected by WHM' - Real or Not
    By metal_cd in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-18-2007, 08:53 AM
  2. Trojan Horses Detected by (WHM)
    By rasilva in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-16-2004, 08:39 PM
  3. Trojan Horses Detected by (WHM)
    By stevo in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-07-2004, 01:27 PM
  4. Trojan Horses Detected by (WHM)
    By Ronny in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-24-2004, 09:42 AM
  5. Trojan Horses Detected by (WHM)... ?
    By brianteeter in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-05-2003, 06:15 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube