[Cialug] Rootkit?

Nathan Stien nathanism at gmail.com
Thu Jan 31 18:54:40 CST 2008


One of my boxen is acting a bit weird.  When I run htop to see what's
running, it shows nearly 100% utilization of each core, but no
particular process seems to be responsible.  The utilization mostly
shows up in red, which in htop means kernel-space.  I've been running
htop for a long time, and it never showed this until recently.
Regular old-skool top shows nothing out of the ordinary.

Things in general seem to be running kinda slow, but not *super* slow.
 Could this be a rootkit?  Or some other oddness?

I've run rkhunter and chkrootkit, and they turned up nothing.  Does
anyone have an idea what else I might do to investigate this?

- Nathan


More information about the Cialug mailing list