Position: Home page » Equipment » Linux mining virus ksoftirqd

Linux mining virus ksoftirqd

Publish: 2021-05-02 03:44:11
1. This kind of virus is mentioned by Tencent security
you can download and install a Tencent Royal point
after opening it, you can directly check and kill this kind of computer virus by using the virus checking and killing function in it
2. This depends on the file name, there is no way to accurately see whether it is a virus, it is best to use security software to detect, you can install a computer housekeeper, and then choose to kill the virus, and delete the virus from the computer
3. Sapphire is the first brand of a card, followed by Dylan
depending on the price, if the price difference is about 200 yuan, you can consider Xunjing or Yingtong.
4. This Exin process is a mining virus. Your machine has been used as a meat mining machine
5.

/Usr / SBIN / kworker suspected mining virus

use clamscn for virus scanning

{rrrrrrr}

all Trojans and Backdoors are recruited

and then use clamsan - R -- beli - I / usr / bin / kworker -- remove to clean up the virus, Learn Linux together

there is also a related netfs to clean up clamsan - R -- beli - I / usr / bin / netfs -- remove to clean up the virus

next step: modify the root password, restart and find that there is no worker

6.

Log in to the system to view the task manager, and view the processes that occupy large memory and cannot be closed. Right click on the process to open the file location (first select Show hidden files and operating system files in the folder option). At this time, you may see a systmss.exe process and a svchost.exe process imitating the operating system. Here you can also see a 2.bat file. Right click to edit and open this file to see which mining organization the malicious process communicates with

by viewing the system operation log, we can analyze the source of the virus, start time and other information. The general reason may be that the hacker did not close port 3389 and used a weak password to remotely log in to the last virus

virus eradication: rename the virus executable file systmss.exe to systmss.exe1, so that the virus cannot be executed. At this time, you can stop the process from the task manager. Open registry editor to delete HKEY_ LOCAL_ The entire directory of machine, system, controlset001, services and systems

for Linux system, please refer to: webpage link

Hot content
Inn digger Publish: 2021-05-29 20:04:36 Views: 341
Purchase of virtual currency in trust contract dispute Publish: 2021-05-29 20:04:33 Views: 942
Blockchain trust machine Publish: 2021-05-29 20:04:26 Views: 720
Brief introduction of ant mine Publish: 2021-05-29 20:04:25 Views: 848
Will digital currency open in November Publish: 2021-05-29 19:56:16 Views: 861
Global digital currency asset exchange Publish: 2021-05-29 19:54:29 Views: 603
Mining chip machine S11 Publish: 2021-05-29 19:54:26 Views: 945
Ethereum algorithm Sha3 Publish: 2021-05-29 19:52:40 Views: 643
Talking about blockchain is not reliable Publish: 2021-05-29 19:52:26 Views: 754
Mining machine node query Publish: 2021-05-29 19:36:37 Views: 750