Since this morning I began to notice a slowness into my Linux/mageia 6.
I checked by using top
command as root user, finding that a process named xm64
running as invitado
user (guest user in spanish) was using 755% of my CPU.
I killed several times that process and it suddendly began again. The suspicious thing was that nobody was logged in as guest user (invitado), the only real user of the computer was me.
As invitado
is an account just for my guests when they are at my home, I decided to erase that user before kill again xm64
process.
After erasing that user, xm64
process never showed up again.
I searched for xm64 information on /var/log using grep -ri xm64 /var/log
but nothing was found.
Now I'm installing clamav
and maldetect
in order to search for information.
I searched on google and I find nothing related with xm64 linux but when I look just for xm64 I find information about a trojan virus on windows XM64.EXE.
This is the first time in 25 years since I began to use Linux that I suspect that my Linux machine is infected.
I blame myself because I created that guest user using a dictionary password ... I promise to never do this again.
Could anyone confirm me if this is a malware on Linux or if this is another issue?
I had the same trojan, and it was places in two locations on the system.
Besides the xm64, the program "goauto" was running in top and was used to autostart the "dtsm" program, which seem to be a mining tool, but I'm not certain.
It had placed cronjob-lines in multiple crontab files inside the /var/spool/cron folder, so be sure to check them all.
I did the following:
It seems like it has stopped the issue.
I am now running clamscan to do the rest of the cleanup if any and have to figure out how it ended up on the server in the first place.