I have a server with Ubuntu 9.10 and rkhunter 1.3.6 installed.Today I have received a mail with next warning:"Found string 'hdparm' in file '/etc/init.d/bootlogd'. Possible rootkit: Xzibit Rootkit"How I check if this is true? Thanks.
Here is the details of how to fix it from rootkit hunters mailing list... http://sourceforge.net/mailarchive/forum.php?forum_name=rkhunter-users&m... http://sourceforge.net/mailarchive/forum.php?thread_name=20091204165435.... Hope this helps.