I run the Tiger Automatic Auditor on my Debian Linux system, and recently got emailed the following:
# Running chkrootkit (/usr/sbin/chkrootkit) to perform further checks...
OLD: --ALERT-- [rootkit005a] Chkrootkit has found a file which seems to be infected because of a rootkit
OLD: --ALERT-- [rootkit009a] A rootkit seems to be installed in the system
OLD: INFECTED (PORTS: 600)
I immediately ran chkrootkit manually, and didn't see any warnings or unusual results. How can I tell whether this was a false positive?