当前位置:网站首页>Record the process of cleaning up mining viruses
Record the process of cleaning up mining viruses
2022-07-06 21:48:00 【Run, Deng DengZi】
Catalog
One 、 The phenomenon
The website is down , Check that the background service is down , Unable to restart normally .
Two 、 Handle
1. View memory usage
Without starting any services , Memory has been basically exhausted :
free -h
total used free shared buff/cache available
Mem: 7.6G 6.4G 581M 401M 690M 640M
Swap: 0B 0B 0B
2. Check the resource usage of each process
top
top - 11:44:00 up 389 days, 23:40, 4 users, load average: 0.00, 0.01, 0.05
Tasks: 209 total, 1 running, 156 sleeping, 0 stopped, 52 zombie
%Cpu(s): 0.1 us, 0.2 sy, 0.0 ni, 99.7 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st
KiB Mem : 8008264 total, 683664 free, 6721116 used, 603484 buff/cache
KiB Swap: 0 total, 0 free, 0 used. 642776 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
2999 root 20 0 162244 2432 1592 S 0.3 0.0 0:00.68 top
5303 root 30 10 3180208 56596 784 S 0.3 0.7 1791:48 xmrig
...
notice xmrig Taking up resources .
3. View scheduled tasks
ls /var/spool/cron/
root
see root The contents of the document :
vi root
30 21 * * * bash /usr/local/apache-tomcat-8.0.46/bin/.moneroocean/miner.sh
see .moneroocean Files under directory :
cd /usr/local/apache-tomcat-8.0.46/bin/.moneroocean
ll
total 8628
-rw-r--r-- 1 root root 6983 Jun 8 03:52 config.json
-rwxr-xr-x 1 root root 375 Jun 8 03:49 miner.sh
-rwxr-xr-x 1 root root 8821240 Apr 1 09:46 xmrig
4. Delete file
cd /var/spool/cron/
rm -rf *
cd /usr/local/apache-tomcat-8.0.46/bin/
rm -rf .moneroocean/
5. kill xmrig process
Find all xmrig Process and kill :
ps -ef | grep xmrig
6. Restart the service
It's best to restart the server and then restart the service , At this time, the service is normal .
边栏推荐
- uni-app App端半屏连续扫码
- 首批入选!腾讯安全天御风控获信通院业务安全能力认证
- 语谱图怎么看
- Digital transformation takes the lead to resume production and work, and online and offline full integration rebuilds business logic
- NPM run dev start project error document is not defined
- The relationship between root and coefficient of quadratic equation with one variable
- Divide candy
- 3D face reconstruction: from basic knowledge to recognition / reconstruction methods!
- Guava: use of multiset
- [go][转载]vscode配置完go跑个helloworld例子
猜你喜欢

PostgreSQL install GIS plug-in create extension PostGIS_ topology

Is it profitable to host an Olympic Games?

Persistence / caching of RDD in spark

中国白酒的5场大战

【力扣刷题】一维动态规划记录(53零钱兑换、300最长递增子序列、53最大子数组和)

guava:Collections. The collection created by unmodifiablexxx is not immutable

Shake Sound poussera l'application indépendante de plantation d'herbe "louable", les octets ne peuvent pas oublier le petit livre rouge?

jvm:大对象在老年代的分配

互联网快讯:吉利正式收购魅族;胰岛素集采在31省全面落地

数字化转型挂帅复产复工,线上线下全融合重建商业逻辑
随机推荐
Sdl2 source analysis 7: performance (sdl_renderpresent())
Binary tree node at the longest distance
b站视频链接快速获取
JS学习笔记-OO创建怀疑的对象
El table table - sortable sorting & disordered sorting when decimal and% appear
对话阿里巴巴副总裁贾扬清:追求大模型,并不是一件坏事
MPLS experiment
在Pi和Jetson nano上运行深度网络,程序被Killed
Enhance network security of kubernetes with cilium
一行代码可以做些什么?
麦趣尔砸了小众奶招牌
FZU 1686 龙之谜 重复覆盖
PostgreSQL 修改数据库用户的密码
Broadcast variables and accumulators in spark
string的底层实现
SQL:存储过程和触发器~笔记
Fastjson parses JSON strings (deserialized to list, map)
Vim 基本配置和经常使用的命令
JPEG2000-Matlab源码实现
快讯:飞书玩家大会线上举行;微信支付推出“教培服务工具箱”