Ok, in that case I can provide a few links that can get you started.... identifying rootkits is not something you are going to learn about in a day.
http://linux.oreillynet.com/pub/a/li.../rootkits.html
http://www.l0t3k.org/security/docs/rootkit/
If you are already compromised, you are due for a fresh install anyway.




