Sfewfesfs virus, LINUX users, are you in the middle?
Nima finally realized that LINUX was so prone to viruses.
Go to the server and find that the machine keeps sending packets out, and the bandwidth is full (10 Gb in 5 minutes ). The cpu usage is 100%. Under the top drop, the process named sfewfesfs is also seen. sshddXXXXXXXXXXX (a string of random numbers) and. sshhddXXXXXXXXXXX (a string of random numbers. Under/etc/, You can see files named sfewfesfs, nhgbhhj, and other strange names.
Start anti-virus first
Delete Virus files
Chattr-I/etc/sfewfesfs *
Rm-rf/etc/sfewfesfs *
Suspicious files such as nhgbhhj are deleted.
Rm-rf/etc/nhgbhhj
Rm-rf/etc/nhgbhhj ***
Delete a scheduled task (very important). The virus is revived by this!
Rm-rf
Ar/spool/cron/root
Rm-rf
Ar/spool/cron/root.1
Use ls-al/etc to view the. SSH2 (possibly. SSHH2) file and delete it.
Rm-rf/etc/. SSH2
Rm-rf/etc/. SSHH2
Use ls-al/tmp to see the. sshdd14XXXXXXXX (a string of random numbers) or. sshhdd14XXXXXXXX (a string of random numbers) hidden file, delete
Rm-rf/tmp/. sshdd14 *
Rm-rf/tmp/. sshhdd14 * restart the server.