Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Dec 2002
    Posts
    17

    Default Trojan Horses Detected

    Hello,

    I received this mail from my server:


    Hidden Pid detected! [pid 27730]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/usr/share/locale/en/.rockmeamadeus/sk]


    I deleted the directory .rockmeamadeus but I do not know if my system was compromised. What should I do?

    Thanks for your help !

    cPanel.net Support Ticket Number:

  2. #2
    Member
    Join Date
    Aug 2002
    Posts
    1,052

    Default

    You should have kept a copy of the binary/source to see what was inside. You should also look in your tmp directory for any rogue files.

    Since crackers usually install additional backdoors, change system binaries, etc. You should consider a format & reinstall on that machine and then lock it down correctly.

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. HELP,HELP Trojan Horses Detected by (WHM)
    By xxgchappy in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 06-12-2004, 10:38 AM
  2. Trojan Horses Detected by (WHM)
    By rasilva in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-16-2004, 08:39 PM
  3. Trojan Horses Detected by (WHM)
    By stevo in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-07-2004, 01:27 PM
  4. Trojan Horses Detected by (WHM)
    By Ronny in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-24-2004, 09:42 AM
  5. Trojan Horses Detected by (WHM)... ?
    By brianteeter in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-05-2003, 06:15 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube