It doesn't really do what you think it is doing.

The hidden process is one of the dead or zombied processes running from chkrootkit

Don't use it. Debian user gets hammered with that question probably 50 times a month. People then argue about it and continue to argue when a new "report" from a newb comes along.

It is not that I don't like chkrootkit, its just that you don't need to worry about it... mainly becuase you don't have *BAD* practices like using "root" as your user. Or just applying any package that comes along because it looks cool.

Yeah, argue with me over this. And you soon learn what a I really think about host based "rootkit" checkers.

They are but one tool type.