сервак начал жрать трафик немерено. во время этих приступов почти не пингуется и ссш не коннектится проверил clamscan
/home/backup/03-03-09/custom/var/spool/virtual.tar.gz: Spoofer.Midav FOUND
/home/backup/03-03-09/custom/var/spool/virtual.tar.gz: moved to '/home/infected///virtual.tar.gz'
/home/infected/virtual.tar.gz: Spoofer.Midav FOUND
File excluded '/home/infected/virtual.tar.gz'
/var/spool/virtual/.fl/v: Spoofer.Midav FOUND
/var/spool/virtual/.fl/v: moved to '/home/infected///v'
/var/tmp/mcroot.txt: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt: moved to '/home/infected///mcroot.txt'
/var/tmp/mcroot.txt.3: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.3: moved to '/home/infected///mcroot.txt.3'
/var/tmp/mcroot.txt.2: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.2: moved to '/home/infected///mcroot.txt.2'
/var/tmp/bb.tar: Spoofer.Midav FOUND
/var/tmp/bb.tar: moved to '/home/infected///bb.tar'
/var/tmp/mcroot.txt.4: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.4: moved to '/home/infected///mcroot.txt.4'
/var/tmp/.../v: Spoofer.Midav FOUND
/var/tmp/.../v: moved to '/home/infected///v.000'
/var/tmp/.../bb/v: Spoofer.Midav FOUND
/var/tmp/.../bb/v: moved to '/home/infected///v.001'
/var/tmp/bb.tar.1: Spoofer.Midav FOUND
/var/tmp/bb.tar.1: moved to '/home/infected///bb.tar.1'
/var/tmp/mcroot.txt.1: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.1: moved to '/home/infected///mcroot.txt.1'
/var/tmp/mcroot.txt.5: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.5: moved to '/home/infected///mcroot.txt.5'
поставил clamav-daemon но через некоторое время опять началось.
пытался через iftop -BP узнать что это но ссш отключло перед тем как он показал кто и куда ломанулся.. что делать..
/home/backup/03-03-09/custom/var/spool/virtual.tar.gz: Spoofer.Midav FOUND
/home/backup/03-03-09/custom/var/spool/virtual.tar.gz: moved to '/home/infected///virtual.tar.gz'
/home/infected/virtual.tar.gz: Spoofer.Midav FOUND
File excluded '/home/infected/virtual.tar.gz'
/var/spool/virtual/.fl/v: Spoofer.Midav FOUND
/var/spool/virtual/.fl/v: moved to '/home/infected///v'
/var/tmp/mcroot.txt: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt: moved to '/home/infected///mcroot.txt'
/var/tmp/mcroot.txt.3: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.3: moved to '/home/infected///mcroot.txt.3'
/var/tmp/mcroot.txt.2: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.2: moved to '/home/infected///mcroot.txt.2'
/var/tmp/bb.tar: Spoofer.Midav FOUND
/var/tmp/bb.tar: moved to '/home/infected///bb.tar'
/var/tmp/mcroot.txt.4: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.4: moved to '/home/infected///mcroot.txt.4'
/var/tmp/.../v: Spoofer.Midav FOUND
/var/tmp/.../v: moved to '/home/infected///v.000'
/var/tmp/.../bb/v: Spoofer.Midav FOUND
/var/tmp/.../bb/v: moved to '/home/infected///v.001'
/var/tmp/bb.tar.1: Spoofer.Midav FOUND
/var/tmp/bb.tar.1: moved to '/home/infected///bb.tar.1'
/var/tmp/mcroot.txt.1: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.1: moved to '/home/infected///mcroot.txt.1'
/var/tmp/mcroot.txt.5: Trojan.Perl.Shellbot FOUND
/var/tmp/mcroot.txt.5: moved to '/home/infected///mcroot.txt.5'
поставил clamav-daemon но через некоторое время опять началось.
пытался через iftop -BP узнать что это но ссш отключло перед тем как он показал кто и куда ломанулся.. что делать..