当前位置:网站首页>Alibaba cloud server mining virus solution (practiced)
Alibaba cloud server mining virus solution (practiced)
2022-07-06 08:49:00 【Xiao Li Xiao Liu】
1、cpu Too high , It's a virus


2、 Get into Linux Connect to Alibaba cloud server
3、 Use top Command dynamic view cpu Occupancy rate
Two cases
1、 No processes with high occupancy are found , Skip to step 7
2、 Found processes with high occupancy , Use kill -9 pid Killing the process will find that the virus continues to appear , useless , Skip to step four
4、 Check the address of the virus file
Input ls -l /proc/{
Viruses PID}/exe Check the virus path

5、 Enter the virus file , Delete them all

6、kill Kill process , complete , Look again cpu, Virus free process done
7、 If the Alibaba cloud server displays cpu Very high , however Linux The viewing process did not find cpu The process with a high proportion , Then it means that the process is hidden .
adopt cat /etc/ld.so.preload It's found that there are .so The file of , This is a virus hidden file
vim Enter this file and you will find many .so file , But it is a read-only file , Cannot modify file
So simply put the whole ld.so.preload File deletion .
8、 After deleting , Use top Check the process , appear cpu Processes with a high proportion

9、 Skip to step 4
10、 use crontab -l Check whether there are scheduled tasks
Delete scheduled tasks crontab -r

summary :
1. use top Check the process Get virus pid
2. hide Delete cat /etc/ld.so.preload .so file
3. Not hidden
4. ls -l /proc/{
Viruses PID}/exe Check the virus file path
5. Delete virus files
6. kill -9 pid Kill the virus process
边栏推荐
- Image,cv2读取图片的numpy数组的转换和尺寸resize变化
- 软件卸载时遇到trying to use is on a network resource that is unavailable
- TCP/IP协议
- Introduction to the differences between compiler options of GCC dynamic library FPIC and FPIC
- What is CSRF (Cross Site Request Forgery)?
- On the inverse order problem of 01 knapsack problem in one-dimensional state
- sublime text中conda环境中plt.show无法弹出显示图片的问题
- LeetCode:41. 缺失的第一个正数
- 【嵌入式】Cortex M4F DSP库
- LeetCode:236. 二叉树的最近公共祖先
猜你喜欢

egg. JS project deployment online server

使用latex导出IEEE文献格式

Marathon envs project environment configuration (strengthen learning and imitate reference actions)

UnsupportedOperationException异常

电脑清理,删除的系统文件

Simple use of promise in uniapp

Unified ordering background interface product description Chinese garbled

Variable length parameter

【ROS】usb_cam相机标定

The harm of game unpacking and the importance of resource encryption
随机推荐
China polyether amine Market Forecast and investment strategy report (2022 Edition)
egg. JS directory structure
View computer devices in LAN
On the inverse order problem of 01 knapsack problem in one-dimensional state
LeetCode:劍指 Offer 42. 連續子數組的最大和
TP-LINK 企业路由器 PPTP 配置
Double pointeur en langage C - - modèle classique
Light of domestic games destroyed by cracking
TCP/IP协议
Guangzhou will promote the construction of a child friendly city, and will explore the establishment of a safe area 200 meters around the school
项目连接数据库遇到的问题及解决
随手记01
China dihydrolaurenol market forecast and investment strategy report (2022 Edition)
LeetCode:498. 对角线遍历
Target detection - pytorch uses mobilenet series (V1, V2, V3) to build yolov4 target detection platform
【嵌入式】使用JLINK RTT打印log
Sublime text using ctrl+b to run another program without closing other runs
Warning in install. packages : package ‘RGtk2’ is not available for this version of R
LeetCode:剑指 Offer 04. 二维数组中的查找
如何进行接口测试测?有哪些注意事项?保姆级解读