K
K
Kamil2019-09-21 16:20:35
Debian
Kamil, 2019-09-21 16:20:35

Virus? Backdoor? How to get rid of the process?

Hello. Not long ago I noticed that processes are hidden in the system.
I can not get rid of them in any way, tell me please how to deal with this?
Hang hidden
61ca38ce72.png
KAgKKEeuEVP5PA.png

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
dpsz, 2019-09-23
@dpsz

Boot from some Linux live-cd, run chkrootkit or rkhunter. It is quite possible that there will be a "animal", but just finding and manually cleaning a rootkit is not enough - it's not just how it got on the computer. Most likely there is a hole somewhere through which he entered. Most often, this hole is simple or compromised passwords. So, in my opinion, you need to backup and reinstall the system to build a more or less correct protection system. For example, do not give anyone access via ssh, transfer the same ssh to a non-standard port, prohibit root from walking on ssh, do not give sudo to everyone (if used), and so on and so forth.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question