Description of problem: ps is accused of possibly being infected with the lkm worm by the latest chkrootkit-0.38 Version-Release number of selected component (if applicable): procps-2.0.7-25.i386.rpm How reproducible: Run the latest chkrootkit-0.38 Steps to Reproduce: 1. run chkrootkit-0.38. 2. look at things with kpm. 3. note kpm see's processes that ps -ea doesn't. Actual results: With gkrellm and mozilla-1.01 running, chkrootkits './chkproc -v -v' will report 6 processes that are hidden by ps. One will be a 2nd copy of gkrellm, and 5 will be mozilla children. Expected results: No hidden processes. Additional info: gnorpm's verify function says procps is exactly the same as the rpm installed it. Reverting to the 7.3 supplied version of procps-2.0.7-12.i386.rpm apparently fixes everything.
If you read the release notes, you would notice that ps hides threads of a single process by default, unless you use the -m parameter (IIRC).
Yes, the pids hidden are the threads. Use -m to see them.