Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Linux and Unix
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop driver drivers dvd email error excel firefox hard drive hardware hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem ram recovery router safe mode screen slow sound spyware trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Is it time to panic?

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
clenny's Avatar
Senior Member with 170 posts.
 
Join Date: Aug 2003
24-Nov-2006, 10:10 AM #1
Is it time to panic?
Me again guys, I've been looking at a few manuals and things. So I'm going through the file system and learning how it's organized when I come across a folder named "chkrootkit". Now I've heard nothing but bad things about rootkits so I'm thinking this shouldn't be there. Am I right? Anyway, I thought I would post this screenshot before I went and removed it.
Attached Thumbnails
Is it time to panic?-rootkit-.jpg  
__________________
The silence of the universe beckons us all.
Bartender's Avatar
Computer Specs
Senior Member with 197 posts.
 
Join Date: Apr 2006
Location: PNW, USA
Experience: Intermediate
24-Nov-2006, 10:28 AM #2
clenny -
Which version of Ubuntu you running? I forgot. I fired up my Dapper 6.06 install, and found no "chkrootkit" file using "Find". I went to Computer, File System, followed it to /etc/cron.daily, and found 11 files, none of them the one you mention.
Your attachment is a little fuzzy right where it counts, but it looks like the very first file is only 5 bytes? Is that right? That's the one you're worried about, isn't it?
I don't see how a file could possibly consist of 5 bytes and still be smart enuf to do anything malicious. I wouldn't delete ANYTHING outside of my home folder that I wasn't absolutely sure about, but let's see if anyone else has anything to say.
clenny's Avatar
Senior Member with 170 posts.
 
Join Date: Aug 2003
24-Nov-2006, 11:08 AM #3
Time to panic redux
I'm running 6.0.6 LTS, that's Dapper, I think. Yeah 5 bytes does seem a bit slim to being to affect any damage but I'd like to hear what others think before I do something that might potentially damage my system. Thanks for your reply.
Solix's Avatar
Junior Member with 2 posts.
 
Join Date: Nov 2006
Location: UK
Experience: Intermediate
24-Nov-2006, 03:28 PM #4
Hi clenny, I don't currently have access to a ubuntu install, but I suspect that they included the chkrootkit software from the chkrootkit.org website to beef up security on the system now that they are pushing it as a business server distro. By the way it's 577 bytes in size.
clenny's Avatar
Senior Member with 170 posts.
 
Join Date: Aug 2003
24-Nov-2006, 07:20 PM #5
chkrootkit
Quote:
Originally Posted by Solix
Hi clenny, I don't currently have access to a ubuntu install, but I suspect that they included the chkrootkit software from the chkrootkit.org website to beef up security on the system now that they are pushing it as a business server distro. By the way it's 577 bytes in size.
Well in that case, it's not anything to be too concerned about, and it's good to know that it comes with robust security. Thanks guys.
prunejuice's Avatar
Senior Member with 1,785 posts.
 
Join Date: Apr 2002
24-Nov-2006, 09:06 PM #6
chkrootkit is the installed package that searches for rootkits...

...as in, type sudo chkrootkit in a terminal, and you'll quickly scan your system for rootkits.
clenny's Avatar
Senior Member with 170 posts.
 
Join Date: Aug 2003
24-Nov-2006, 10:49 PM #7
Yeah, you're right. I checked around and found this:http://packages.debian.org/stable/misc/chkrootkit. And there are hundreds of references on the web too. I ran the command you suggested in the terminal and am happy to report that my system has a clean bill of health.
__________________
The silence of the universe beckons us all.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 06:56 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.