At this point I am building another machine to switch the website and email to while I sort out what to do about this.

After recompiling chkrootkit:
ROOTDIR is `/'

Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not infected
Checking `gpm'... not infected
Checking `grep'... not infected
Checking `hdparm'... not infected
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not infected
Checking `inetdconf'... not found
Checking `identd'... not infected
Checking `killall'... not infected
Checking `ldsopreload'... not infected
Checking `login'... not infected
Checking `ls'... not infected
Checking `lsof'... not infected
Checking `mail'... not infected
Checking `mingetty'... not infected
Checking `netstat'... not infected
Checking `named'... not infected
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... not infected
Checking `rpcinfo'... not infected
Checking `rlogind'... not infected
Checking `rshd'... not infected
Checking `slogin'... not infected
Checking `sendmail'... not infected
Checking `sshd'... not infected
Checking `syslogd'... not infected
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `top'... not infected
Checking `telnetd'... not infected
Checking `timed'... not found
Checking `traceroute'... not infected
Checking `write'... not infected
Checking `aliens'...
/dev/ttyop /dev/ttyoa /dev/tux/.addr /dev/tux/.proc /dev/tux/tools/mirkforce/realnames
Searching for sniffer's logs, it may take a while... nothing found
Searching for HiDrootkit's default dir... nothing found
Searching for t0rn's default files and dirs... nothing found
Searching for t0rn's v8 defaults... nothing found
Searching for Lion Worm default files and dirs... nothing found
Searching for RSHA's default files and dir... nothing found
Searching for RH-Sharpe's default files... Possible RH-Sharpe's rootkit installed
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while...
/usr/lib/perl5/5.6.0/i386-linux/.packlist /usr/lib/perl5/5.6.0/i386-linux/auto/CGI/.packlist /usr/lib/perl5/site_perl/5.6.0/i386-linux/auto/Digest/MD5/.packlist /usr/lib/perl5/site_perl/5.6.0/i386-linux/auto/Image/Magick/.packlist /usr/lib/perl5/site_perl/5.6.0/i386-linux/auto/DBD/Pg/.packlist

Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... INFECTED (PORTS: 465)
Checking `lkm'... You have 6 process hidden for ps command
Warning: Possible LKM Trojan installed
Checking `rexedcs'... not found
Checking `sniffer'...
eth0 is PROMISC
Checking `wted'... nothing deleted
Checking `z2'...
nothing deleted


And 'netstat -p':
Active UNIX domain sockets (w/o servers)

Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 3 [ ] STREAM CONNECTED 1374 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1373 996/xfs
unix 3 [ ] STREAM CONNECTED 1337 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1336 960/crond
unix 3 [ ] STREAM CONNECTED 1269 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1268 921/sendmail: accep
unix 3 [ ] STREAM CONNECTED 1181 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1180 869/xinetd
unix 3 [ ] STREAM CONNECTED 1132 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1131 844/sshd
unix 3 [ ] STREAM CONNECTED 1062 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1061 810/automount
unix 3 [ ] STREAM CONNECTED 1018 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 1017 761/apmd
unix 3 [ ] STREAM CONNECTED 880 646/syslogd /dev/log
unix 3 [ ] STREAM CONNECTED 879 677/rpc.statd
unix 2 [ ] DGRAM 840 650/klogd
_________________________
-Rob Riccardelli
80GB 16MB MK2 090000736