Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

CHKROOTKIT suspicious files (newbie)

Discussion in 'General Discussion' started by Lammypie, Sep 19, 2006.

  1. Lammypie

    Lammypie Member

    Sep 10, 2006
    Likes Received:
    Trophy Points:
    I recently bought a VPS (virtuozzo & cpanel whm)but left it enabled with no firewall etc for a few days, (very newbie) while I figured out and researched the basics.

    I'm now trying to secure it.

    I've just installed CHKROOTKIT ( and I'm getting a lot of entries which cause me concern, and I need some expert advice on what they are, ie are they bad, or just routine, what do I need to do to fix it?

    I thought everything should return 'nothing found', or 'not infected'
    but 'searching for suspicious files and dirs' returns this huge quantity of entries

    Does this mean all of the fiels above are suspicious?

    The next one is
    Thanks in advance

  2. chirpy

    chirpy Well-Known Member

    Jun 15, 2002
    Likes Received:
    Trophy Points:
    Go on, have a guess
    All false positives.

    The hidden processes/LKM messages are almost always false-positives:

    The LKM appear whenever "hidden" processes are found. They're usually processes that have started between the different checks that chkrootkit runs while processing. Usually, they're named mysql httpd or exim processes. You can get more information about which processes are being caught using:

    cd /root/chkrootkit-0.*
    ./chkrootkit -x lkm

    When you run it you will probably find that it returns anything from none to several processes.
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. mctDarren

    mctDarren Well-Known Member

    Jan 6, 2004
    Likes Received:
    Trophy Points:
    New Jersey
    cPanel Access Level:
    Root Administrator
    Just as an addition to Chirpy's post, those packlist files are just leftovers from Perl modules that have been installed. They're safely ignored for the most part. Same with the PHP related files. Also, the Bindshell alert is common on cPanel machines and can also be ignored for the most part.

    What you'll find is that you will get used to seeing the same things in the report all the time, then when something is amiss it will jump right out at you - one of those "hmmm, that's new!" moments. :D

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice