I had the same alert as you did. Found the following thread:
http://art.ubuntuforums.org/showthread.php?t=1465667
Hope it helps.

Steve

On May 3, 1:43 pm, Charlie <[email protected]> wrote:
> anyone else seeing this?
>
> Received From: Nyar->rootcheck
> Rule: 510 fired (level 7) -> "Host-based anomaly detection event
> (rootcheck)."
> Portion of the log(s):
>
> Trojaned version of file '/bin/login' detected. Signature used:
> 'bash|elite|SucKIT|xlogin|vejeta|porcao|lets_log|sukasuk' (Generic).

Reply via email to