Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Install the Chkrootkit Scanner on Ubuntu 18.04

Chkrootkit checks your server for signs of hidden attackers. This guide shows how to install and run it. It needs root access.

Web Hosting2 min read13 steps
Tip: Ubuntu 18.04 is old software. Newer Ubuntu versions use the same commands.

What is a rootkit?

A rootkit is a sneaky program that an attacker hides on a server. It gives them secret control, and it hides itself from you. Chkrootkit is a free tool that looks for known rootkits. It works like a metal detector that beeps when it finds something suspicious. It is not perfect, so use it as one of your safety checks.

Install it

  1. Connect to your server with SSH as root, or as a user who can use sudo.
  2. Update the list of packages:
sudo apt update

This refreshes the list of software that can be installed.

  1. Install the tool:
sudo apt install chkrootkit -y

This downloads and installs chkrootkit. If a mail setup screen appears, you can choose No configuration.

  1. Check the version:
chkrootkit -V

This prints the version, which confirms the install worked.

Run a scan

  1. Start the scan:
sudo chkrootkit

This checks many system files and programs. It takes a minute or two.

  1. Read the results. Most lines say not infected or nothing found.
  2. To show only lines that need attention, run:
sudo chkrootkit | grep INFECTED

This hides the normal lines and shows only the infected ones.

About false alarms

Chkrootkit can show a warning that is not a real threat. For example, it may flag a harmless file in a hidden folder. Look up the exact message before you panic. Do not delete system files in a hurry.

If something is infected

  1. Disconnect the server from public traffic if you can.
  2. Take a backup of your important data.
  3. Ask for expert help. A safe fix is often to rebuild the server from a clean system and restore only your clean data.
  4. Open a support ticket to ask Hostvento what help is available.

Run it on a schedule (optional)

  1. Open the cron editor:
sudo crontab -e

Cron is a tool that runs tasks at set times.

  1. Add this line to scan each day at 3 AM and save the result:
0 3 * * * /usr/sbin/chkrootkit > /var/log/chkrootkit.log 2>&1

This writes the scan result to a log file.

Quick recap

  • Chkrootkit looks for hidden attacker programs.
  • Install it with apt install chkrootkit.
  • Run sudo chkrootkit and look for INFECTED.
  • Check warnings carefully, because false alarms happen.