Check for Rootkit in linux systems with chkrootkit
chkrootkit is a tool to locally check for signs of a rootkit. It contains:
chkrootkit: a shell script that checks system binaries for
rootkit modification.
ifpromisc.c: checks if the network interface is in promiscuous
mode.
chklastlog.c: checks for lastlog deletions.
chkwtmp.c: checks for wtmp deletions.
check_wtmpx.c: checks for wtmpx deletions. (Solaris only)
chkproc.c: checks for signs of LKM trojans.
chkdirs.c: checks for signs of [...]
