Symptoms
- File /tmp/.cinik, /tmp/.cinik.c, /tmp/.cinik.go (variant B);
- File /tmp/.unlock.c, /tmp/httpd, /tmp/.update.c, /tmp/update;
- directory /tmp/.font-unix/.cinik (variant B);
- Message "foo" …
Removal instructions:
If you don't have BitDefender for Linux installed click here to download an evaluation version.
1. Make sure that you have the latest updates using the
bdc --update or the manual update for this product
2. Terminate the virus process using the
killall -9 process_name or by restarting the computer.
3. Use BitDefender for Linux with the following parameters in the command line:
bdc --all --delete --list /tmp 4. Updated the version of the Apache server to eliminate the vulnerability
Analyzed By
Costin Ionescu BitDefender Virus Researcher
SHARE
THIS ON