Question about "top" command and root kits
Hello,does anyone here have both a RedHat 9.0 setup and a new RHE setup? I have both and when I run "top" command under RH 9.0 it looks different to when I run top under RHE. I am worried I've got a rootkit on my server. I've run rkhunter and chkrootkit and nothing comes up. Also with rkhunter - the md5 check - does it get the correct md5 from your system files at the time of installation? Then for subsequent scans it compares to this original md5 list? Or does it compare your current servers md5's with standard md5's for the Linux distrobution? IE compares it to some glabal md5 values? My point is I'm worried I could have installed rkhunter after my server was already hacked - so would it then not pick up md5 problem?
chkrootkit - doesn't come up with a rootkit either.
I would be happy if it wasn't for a difference in the way top outputs data for my RH 9.0 and RHE - if someone else can verify this is normal then I should be ok.
Thanks.