Answer the question
In order to leave comments, you need to log in
Answer the question
In order to leave comments, you need to log in
Boot from some Linux live-cd, run chkrootkit or rkhunter. It is quite possible that there will be a "animal", but just finding and manually cleaning a rootkit is not enough - it's not just how it got on the computer. Most likely there is a hole somewhere through which he entered. Most often, this hole is simple or compromised passwords. So, in my opinion, you need to backup and reinstall the system to build a more or less correct protection system. For example, do not give anyone access via ssh, transfer the same ssh to a non-standard port, prohibit root from walking on ssh, do not give sudo to everyone (if used), and so on and so forth.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question