当前位置:网站首页>Record the process of cleaning up mining viruses
Record the process of cleaning up mining viruses
2022-07-06 21:48:00 【Run, Deng DengZi】
Catalog
One 、 The phenomenon
The website is down , Check that the background service is down , Unable to restart normally .
Two 、 Handle
1. View memory usage
Without starting any services , Memory has been basically exhausted :
free -h
total used free shared buff/cache available
Mem: 7.6G 6.4G 581M 401M 690M 640M
Swap: 0B 0B 0B
2. Check the resource usage of each process
top
top - 11:44:00 up 389 days, 23:40, 4 users, load average: 0.00, 0.01, 0.05
Tasks: 209 total, 1 running, 156 sleeping, 0 stopped, 52 zombie
%Cpu(s): 0.1 us, 0.2 sy, 0.0 ni, 99.7 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st
KiB Mem : 8008264 total, 683664 free, 6721116 used, 603484 buff/cache
KiB Swap: 0 total, 0 free, 0 used. 642776 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
2999 root 20 0 162244 2432 1592 S 0.3 0.0 0:00.68 top
5303 root 30 10 3180208 56596 784 S 0.3 0.7 1791:48 xmrig
...
notice xmrig Taking up resources .
3. View scheduled tasks
ls /var/spool/cron/
root
see root The contents of the document :
vi root
30 21 * * * bash /usr/local/apache-tomcat-8.0.46/bin/.moneroocean/miner.sh
see .moneroocean Files under directory :
cd /usr/local/apache-tomcat-8.0.46/bin/.moneroocean
ll
total 8628
-rw-r--r-- 1 root root 6983 Jun 8 03:52 config.json
-rwxr-xr-x 1 root root 375 Jun 8 03:49 miner.sh
-rwxr-xr-x 1 root root 8821240 Apr 1 09:46 xmrig
4. Delete file
cd /var/spool/cron/
rm -rf *
cd /usr/local/apache-tomcat-8.0.46/bin/
rm -rf .moneroocean/
5. kill xmrig process
Find all xmrig Process and kill :
ps -ef | grep xmrig
6. Restart the service
It's best to restart the server and then restart the service , At this time, the service is normal .
边栏推荐
- 美国科技行业结束黄金时代,芯片求售、裁员3万等哀声不断
- Dialogue with Jia Yangqing, vice president of Alibaba: pursuing a big model is not a bad thing
- JS learning notes OO create suspicious objects
- SQL:存储过程和触发器~笔记
- b站视频链接快速获取
- R3live notes: image processing section
- Enhance network security of kubernetes with cilium
- guava:创建immutableXxx对象的3种方式
- 强化学习-学习笔记5 | AlphaGo
- numpy 下载安装
猜你喜欢

抖音将推独立种草App“可颂”,字节忘不掉小红书?

Summary of cross partition scheme

3D face reconstruction: from basic knowledge to recognition / reconstruction methods!

Yuan Xiaolin: safety is not only a standard, but also Volvo's unchanging belief and pursuit

Numpy download and installation

Shake Sound poussera l'application indépendante de plantation d'herbe "louable", les octets ne peuvent pas oublier le petit livre rouge?

红杉中国,刚刚募资90亿美元
![[interpretation of the paper] machine learning technology for Cataract Classification / classification](/img/0c/b76e59f092c1b534736132faa76de5.png)
[interpretation of the paper] machine learning technology for Cataract Classification / classification

Internet News: Geely officially acquired Meizu; Intensive insulin purchase was fully implemented in 31 provinces

Reptile practice (V): climbing watercress top250
随机推荐
Technology sharing | packet capturing analysis TCP protocol
50 commonly used numpy function explanations, parameters and usage examples
@Detailed differences among getmapping, @postmapping and @requestmapping, with actual combat code (all)
[Li Kou brushing questions] one dimensional dynamic planning record (53 change exchanges, 300 longest increasing subsequence, 53 largest subarray and)
guava:Collections. The collection created by unmodifiablexxx is not immutable
红杉中国,刚刚募资90亿美元
[interpretation of the paper] machine learning technology for Cataract Classification / classification
Explain ESM module and commonjs module in simple terms
华为在多个行业同时出击,吓人的技术让欧美企业瑟瑟发抖
Z function (extended KMP)
LeetCode:1189. The maximum number of "balloons" -- simple
SQL:存储过程和触发器~笔记
【力扣刷题】32. 最长有效括号
JS learning notes OO create suspicious objects
MySQL - 事务(Transaction)详解
1292_FreeROS中vTaskResume()以及xTaskResumeFromISR()的实现分析
Microsoft technology empowerment position - February course Preview
High precision face recognition based on insightface, which can directly benchmark hongruan
Acdreamoj1110 (multiple backpacks)
技术分享 | 抓包分析 TCP 协议