Skip to content

Instantly share code, notes, and snippets.

View Giladx's full-sized avatar
🏄‍♂️
Skateboarding & Surfing

Gilad Levi Giladx

🏄‍♂️
Skateboarding & Surfing
View GitHub Profile
@Giladx
Giladx / cleancrap.md
Created November 15, 2024 12:41 — forked from yoyosan/cleancrap.md
How to clean kdetmpdevfsi or .ICEd-unix suspicious files/folders or processes

Problem

I've recently been hacked on my VPS(using Centos 7.6 and CWP up to date) and the following files/folders were created:

  • /tmp/.ICEd-unix
  • /var/tmp/.ICEd-unix
  • /tmp/kdevtmpfsi
  • /var/tmp/kinsing

The following processes were running and using 100% CPU and Memory: