Can I remove "Linux/Ebury Operation Windigo" without wiping the entire drive?
0
votes
3
answers
3052
views
I used
chkrootkit
, which told me that I had "Linux/Ebury Operation Windigo" installed, I doubled checked by running ssh -G
which printed out usage, without "illegal option". I removed all ssh files and reinstalled it, but when I ran ssh -G
again I still had it, also detected by chkrootkit
.
Can you remove this without wiping the entire drive? Are there any files I should be looking for?
Asked by DisplayName
(12016 rep)
Mar 7, 2016, 10:07 PM
Last activity: Apr 28, 2022, 11:54 AM
Last activity: Apr 28, 2022, 11:54 AM