Bonjours,
Mon proxy à été infecté par un trojan:
ROOTDIR is `/'
Checking `amd'... not found
...
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
[color=#BF0000]Searching for suspicious files and dirs, it may take a while...
/lib/init/rw/.mdadm
/lib/init/rw/.ramfs
/lib/init/rw/.mdadm[/color]
Searching for LPD Worm files and dirs... nothing found
...
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
[color=#BF0000]Checking `lkm'... You have 3 process hidden for readdir command
You have 4 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
Checking `rexedcs'... not found
Checking `sniffer'... eth0: PACKET [/color]SNIFFER(/usr/sbin/tcpdump[3004])
lo: not promisc and no packet sniffer sockets
SQUID est shooté systématiquement des processus actifs.
Clamav reste sans rien faire.
Quelqu’un peut m’aider SVP ?
et si possible trouver qui utilise se trojan pour mettre la pagaille ???