我已经看到我的系统有两种rootkit:SHV4 / SHV5。 (我要在这里添加一个日志)我试图删除它,但我不能。
任何人都可以推荐我以任何方式来做到这一点?
[ Rootkit Hunter version 1.3.8 ] Checking system commands... /usr/bin/md5sum [ Warning ] /usr/bin/pstree [ Warning ] /usr/bin/top [ Warning ] /usr/bin/unhide.rb [ Warning ] /sbin/ifconfig [ Warning ] /bin/ls [ Warning ] /bin/ps [ Warning ] /bin/netstat [ Warning ] Checking for rootkits... cb Rootkit [ Warning ] SHV4 Rootkit [ Warning ] SHV5 Rootkit [ Warning ] Checking for possible rootkit strings [ Warning ] Checking the local host... Checking for root equivalent (UID 0) accounts [ Warning ] Checking for passwd file changes [ Warning ] Checking for group file changes [ Warning ] Checking if SSH root access is allowed [ Warning ] Checking for running syslog daemon [ Warning ] Checking the local host... Checking for root equivalent (UID 0) accounts [ Warning ] Checking for passwd file changes [ Warning ] Checking for group file changes [ Warning ] Checking if SSH root access is allowed [ Warning ] Checking for running syslog daemon [ Warning ]
你需要其他types的日志文件吗?
提前致谢
你的系统现在已经被盗用了。 将其从轨道上移开并从受信任状态恢复(备份)。

如果您的系统遭到入侵,那么除了恢复上一次已知的良好备份并修补攻击者利用这些漏洞进入系统的漏洞之外,没有安全的方法来删除rootkit。