收起左侧

被当肉**了吗?

1
回复
86
查看
[ 复制链接 ]

2

主题

0

回帖

0

牛值

江湖小虾

2026-2-5 17:00:46 显示全部楼层 阅读模式

帮我分析一下,谢谢!

root@fnOS:/home/Andyi# ps -eff --forest | grep -A 5 "kworker"

root 4 2 0 09:09 ? 00:00:00 _ [kworker/R-rcu_gp]
root 5 2 0 09:09 ? 00:00:00 _ [kworker/R-sync_wq]
root 6 2 0 09:09 ? 00:00:00 _ [kworker/R-slub_flushwq]
root 7 2 0 09:09 ? 00:00:00 _ [kworker/R-netns]
root 10 2 0 09:09 ? 00:00:00 _ [kworker/0:0H-events_highpri]
root 12 2 0 09:09 ? 00:00:00 _ [kworker/R-mm_percpu_wq]
root 13 2 0 09:09 ? 00:00:00 _ [rcu_tasks_kthread]
root 14 2 0 09:09 ? 00:00:00 _ [rcu_tasks_rude_kthread]
root 15 2 0 09:09 ? 00:00:00 _ [rcu_tasks_trace_kthread]
root 16 2 0 09:09 ? 00:00:01 _ [ksoftirqd/0]
root 17 2 0 09:09 ? 00:00:04 _ [rcu_preempt]

root 39 2 0 09:09 ? 00:00:00 _ [kworker/R-inet_frag_wq]

root 40 2 0 09:09 ? 00:00:00 _ [kauditd]
root 41 2 0 09:09 ? 00:00:00 _ [khungtaskd]
root 42 2 0 09:09 ? 00:00:00 _ [oom_reaper]
root 43 2 0 09:09 ? 00:00:00 _ [kworker/R-writeback]
root 44 2 0 09:09 ? 00:00:01 _ [kcompactd0]
root 45 2 0 09:09 ? 00:00:00 _ [ksmd]
root 46 2 0 09:09 ? 00:00:00 _ [khugepaged]
root 47 2 0 09:09 ? 00:00:00 _ [kworker/R-kintegrityd]
root 48 2 0 09:09 ? 00:00:00 _ [kworker/R-kblockd]
root 49 2 0 09:09 ? 00:00:00 _ [kworker/R-blkcg_punt_bio]
root 50 2 0 09:09 ? 00:00:00 _ [irq/9-acpi]
root 53 2 0 09:09 ? 00:00:00 _ [kworker/R-edac-poller]
root 54 2 0 09:09 ? 00:00:00 _ [kworker/R-devfreq_wq]
root 56 2 0 09:09 ? 00:00:03 _ [kswapd0]
root 62 2 0 09:09 ? 00:00:00 _ [kworker/R-kthrotld]
root 66 2 0 09:09 ? 00:00:00 _ [irq/24-aerdrv]
root 67 2 0 09:09 ? 00:00:00 _ [irq/25-aerdrv]
root 68 2 0 09:09 ? 00:00:00 _ [irq/26-aerdrv]
root 69 2 0 09:09 ? 00:00:00 _ [irq/27-aerdrv]
root 70 2 0 09:09 ? 00:00:01 _ [kworker/0:1H-kblockd]
root 71 2 0 09:09 ? 00:00:00 _ [kworker/R-acpi_thermal_pm]
root 72 2 0 09:09 ? 00:00:00 _ [kworker/R-mld]
root 73 2 0 09:09 ? 00:00:00 _ [kworker/R-ipv6_addrconf]
root 78 2 0 09:09 ? 00:00:00 _ [kworker/R-kstrp]
root 79 2 0 09:09 ? 00:00:00 _ [kworker/u13:0]
root 2256 2 0 09:09 ? 00:00:00 _ [kworker/R-ttm]
root 2288 2 0 09:09 ? 00:00:00 _ [kworker/R-ata_sff]
root 2356 2 0 09:09 ? 00:00:00 _ [scsi_eh_0]
root 2391 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_0]
root 2392 2 0 09:09 ? 00:00:00 _ [scsi_eh_1]
root 2393 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_1]
root 2394 2 0 09:09 ? 00:00:00 _ [scsi_eh_2]
root 2395 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_2]
root 2396 2 0 09:09 ? 00:00:00 _ [scsi_eh_3]
root 2399 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_3]
root 2408 2 0 09:09 ? 00:00:00 _ [scsi_eh_4]
root 2416 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_4]
root 2417 2 0 09:09 ? 00:00:00 _ [scsi_eh_5]
root 2421 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_5]
root 2433 2 0 09:09 ? 00:00:00 _ [scsi_eh_6]
root 2444 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_6]
root 2446 2 0 09:09 ? 00:00:00 _ [scsi_eh_7]
root 2448 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_7]
root 2454 2 0 09:09 ? 00:00:00 _ [scsi_eh_8]
root 2455 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_8]
root 2458 2 0 09:09 ? 00:00:00 _ [scsi_eh_9]
root 2459 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_9]
root 2461 2 0 09:09 ? 00:00:00 _ [scsi_eh_10]
root 2466 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_10]
root 2468 2 0 09:09 ? 00:00:00 _ [scsi_eh_11]
root 2470 2 0 09:09 ? 00:00:00 _ [kworker/R-scsi_tmf_11]
root 2824 2 0 09:09 ? 00:00:01 _ [kworker/1:2H-kblockd]
root 2827 2 0 09:09 ? 00:00:00 _ [kworker/R-md]
root 2828 2 0 09:09 ? 00:00:00 _ [kworker/R-md_bitmap]
root 2858 2 0 09:09 ? 00:00:00 _ [kworker/R-kdmflush/253:0]
root 2922 2 0 09:09 ? 00:00:00 _ [kworker/R-raid5wq]
root 2995 2 0 09:09 ? 00:00:03 _ [jbd2/sda2-8]
root 2996 2 0 09:09 ? 00:00:00 _ [kworker/R-ext4-rsv-conversion]
root 5579 2 0 09:10 ? 00:00:00 _ [watchdogd]
root 5693 2 0 09:10 ? 00:00:00 _ [kworker/R-cryptd]
root 6569 2 0 09:10 ? 00:00:00 _ [kworker/R-rpciod]
root 6570 2 0 09:10 ? 00:00:00 _ [kworker/R-xprtiod]
root 7403 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-worker]
root 7404 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-delalloc]
root 7405 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-flush_delalloc]
root 7406 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-cache]
root 7407 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-fixup]
root 7408 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-endio]
root 7409 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-endio-meta]
root 7410 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-rmw]
root 7411 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-endio-write]
root 7412 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-compressed-write]
root 7413 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-freespace-write]
root 7414 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-delayed-meta]
root 7415 2 0 09:10 ? 00:00:00 _ [kworker/R-btrfs-qgroup-rescan]
root 7456 2 0 09:10 ? 00:00:00 _ [btrfs-cleaner]
root 7457 2 0 09:10 ? 00:00:00 _ [btrfs-transaction]
root 7529 2 0 09:10 ? 00:00:00 _ [spl_system_task]
root 7530 2 0 09:10 ? 00:00:00 _ [spl_delay_taskq]
root 7531 2 0 09:10 ? 00:00:00 _ [spl_dynamic_tas]

root 7999 2 0 09:11 ? 00:00:01 _ [kworker/2:2H-kblockd]

root 214047 2 0 11:45 ? 00:00:00 _ [kworker/1:0H-kblockd]
root 219117 2 0 12:37 ? 00:00:00 _ [kworker/u12:1-events_unbound]
root 224058 2 0 13:27 ? 00:00:00 _ [kworker/0:1-cgroup_destroy]
root 225832 2 0 13:45 ? 00:00:00 _ [kworker/1:0-cgroup_destroy]
root 226891 2 0 13:55 ? 00:00:00 _ [kworker/u12:3-flush-btrfs-1]
root 226892 2 0 13:55 ? 00:00:00 _ [kworker/u12:4-flush-8:0]
root 226893 2 0 13:55 ? 00:00:00 _ [kworker/2:1H-kblockd]
root 227214 2 0 13:59 ? 00:00:00 _ [kworker/2:2-events]
root 227278 2 0 13:59 ? 00:00:00 _ [kworker/1:1-events]
root 227564 2 0 14:02 ? 00:00:00 _ [kworker/0:2-events]
root 227732 2 0 14:04 ? 00:00:00 _ [kworker/2:3-cgroup_destroy]
root 227833 2 0 14:05 ? 00:00:00 _ [kworker/1:2-cgroup_destroy]
root 227864 2 0 14:05 ? 00:00:00 _ [kworker/1:1H-kblockd]
root 228237 2 0 14:07 ? 00:00:00 _ [kworker/u12:0-events_unbound]
root 228238 2 0 14:07 ? 00:00:00 _ [kworker/0:0]
root 1 0 0 09:09 ? 00:00:19 /lib/systemd/systemd --system --deserialize=26
root 3052 1 0 09:09 ? 00:00:04 /lib/systemd/systemd-journald
root 3076 1 0 09:09 ? 00:00:00 /lib/systemd/systemd-udevd
_rpc 6568 1 0 09:10 ? 00:00:00 /sbin/rpcbind -f -w
systemd+ 6581 1 0 09:10 ? 00:00:00 /lib/systemd/systemd-timesyncd

root 228378 226706 0 14:09 pts/0 00:00:00 _ grep --color=auto -A 5 kworker

postgres 7272 1 0 09:10 ? 00:00:02 /usr/lib/postgresql/15/bin/postgres -D /var/lib/postgresql/15/main -c config_file=/etc/postgresql/15/main/postgresql.conf
postgres 7320 7272 0 09:10 ? 00:00:00 _ postgres: 15/main: checkpointer
postgres 7321 7272 0 09:10 ? 00:00:00 _ postgres: 15/main: background writer
postgres 7324 7272 0 09:10 ? 00:00:00 _ postgres: 15/main: walwriter
postgres 7325 7272 0 09:10 ? 00:00:00 _ postgres: 15/main: autovacuum launcher

root 228042 226709 99 14:06 ? 00:05:39 _ [kworker/u4:1]
root 227834 1 1 14:05 ? 00:00:04 /usr/trim/bin/resmon_service
rabbitmq 228062 1 2 14:06 ? 00:00:04 /usr/lib/erlang/erts-13.1.5/bin/beam.smp -W w -MBas ageffcbf -MHas ageffcbf -MBlmbcs 512 -MHlmbcs 512 -MMmcs 30 -P 1048576 -t 5000000 -stbt db -zdbbl 128000 -sbwt none -sbwtdcpu none -sbwtdio none -- -root /usr/lib/erlang -bindir /usr/lib/erlang/erts-13.1.5/bin -progname erl -- -home /var/lib/rabbitmq -- -pa -noshell -noinput -s rabbit boot -boot start_sasl -syslog logger [] -syslog syslog_error_logger false -kernel prevent_overlapping_partitions false
rabbitmq 228072 228062 0 14:06 ? 00:00:00 _ erl_child_setup 65536
rabbitmq 228130 228072 0 14:06 ? 00:00:00 _ /usr/lib/erlang/erts-13.1.5/bin/inet_gethost 4
rabbitmq 228131 228130 0 14:06 ? 00:00:00 | _ /usr/lib/erlang/erts-13.1.5/bin/inet_gethost 4
root@fnOS:/home/Andyi# systemctl list-units --type=service | grep -E "cron|helper|reaper|update"
cron.service loaded active running Regular background program processing daemon
cron_for_fix.service loaded activating start start Run custom script After trim_main
S99zeidww.service loaded active running LSB: System helper daemon
systemd-update-utmp-runlevel.service loaded inactive dead start Record Runlevel Change in UTMP
systemd-update-utmp.service loaded active exited Record System Boot/Shutdown in UTMP
root@fnOS:/home/Andyi# ls -la /etc/systemd/system/ | grep ".service"
-rw-r--r-- 1 root root 345 Feb 1 00:38 accountsrv.service
-rw-r--r-- 1 root root 281 Feb 1 00:38 ai_manager.service
-rw-r--r-- 1 root root 300 Feb 1 00:38 auto_thumbnailer.service
-rw-r--r-- 1 root root 216 Feb 1 00:38 avahi.service
-rw-r--r-- 1 root root 200 Feb 1 00:38 backup_service.service
-rw-r--r-- 1 root root 389 Feb 1 00:38 cloud_storage_dav.service
-rw-r--r-- 1 root root 218 Feb 1 00:38 cron_for_fix.service
lrwxrwxrwx 1 root root 42 Jul 7 2023 dbus-fi.w1.wpa_supplicant1.service -> /lib/systemd/system/wpa_supplicant.service
lrwxrwxrwx 1 root root 40 Jul 7 2023 dbus-org.freedesktop.Avahi.service -> /lib/systemd/system/avahi-daemon.service
lrwxrwxrwx 1 root root 40 Jul 7 2023 dbus-org.freedesktop.ModemManager1.service -> /lib/systemd/system/ModemManager.service
lrwxrwxrwx 1 root root 53 Jul 7 2023 dbus-org.freedesktop.nm-dispatcher.service -> /lib/systemd/system/NetworkManager-dispatcher.service
lrwxrwxrwx 1 root root 45 Jul 7 2023 dbus-org.freedesktop.timesync1.service -> /lib/systemd/system/systemd-timesyncd.service
lrwxrwxrwx 1 root root 39 Feb 4 21:43 dbus.service -> /lib/systemd/system/dbus-broker.service
-rw-r--r-- 1 root root 217 Feb 1 00:38 dlcenter.service
-rw-r--r-- 1 root root 215 Feb 3 11:49 dockerdd.service
-rw-r--r-- 1 root root 244 Feb 1 00:38 dockermgr.service
-rw-r--r-- 1 root root 1557 Feb 1 00:38 docker.service
-rw-r--r-- 1 root root 213 Feb 1 00:38 dsmgr.service
-rw-r--r-- 1 root root 197 Feb 1 00:38 eventlogger_service.service
-rw-r--r-- 1 root root 256 Feb 1 00:38 filestor_service.service
-rw-r--r-- 1 root root 219 Feb 1 00:38 finder_service.service
drwxr-xr-x 2 root root 4096 Feb 4 21:41 getty@tty1.service.d
-rw-r--r-- 1 root root 324 Feb 1 00:38 imagesrv.service
-rw-r--r-- 1 root root 306 Feb 1 00:38 mediasrv.service
-rw-r--r-- 1 root root 424 Feb 1 00:38 minidlna.service
-rw-r--r-- 1 root root 278 Feb 1 00:38 multiple-downloads.service
-rw-r--r-- 1 root root 253 Feb 1 00:38 network_service.service
-rw-r--r-- 1 root root 371 Feb 3 15:08 nezha-agent.service
-rw-r--r-- 1 root root 296 Feb 1 00:38 nmbd.service
-rw-r--r-- 1 root root 225 Jul 15 2024 notify_service.service
drwxr-xr-x 2 root root 4096 Dec 12 2024 nut-driver@.service.d
drwxr-xr-x 2 root root 4096 Dec 11 2024 openvswitch-switch.service.requires
-rw-r--r-- 1 root root 316 Feb 3 19:31 otaabvbo.service
-rw-r--r-- 1 root root 253 Jul 7 2023 rc-local.service
-rw-r--r-- 1 root root 239 Feb 1 00:38 resmon_service.service
-rw-r--r-- 1 root root 214 Feb 1 00:38 rpc_broker.service
-rw-r--r-- 1 root root 312 Feb 1 00:38 security_service.service
-rw-r--r-- 1 root root 248 Feb 1 00:38 share_service.service
-rw-r--r-- 1 root root 201 Feb 1 00:38 show_startup_info.service
lrwxrwxrwx 1 root root 41 Jul 7 2023 smartd.service -> /lib/systemd/system/smartmontools.service
-rw-r--r-- 1 root root 355 Feb 1 00:38 smbd.service
-rw-r--r-- 1 root root 327 Feb 1 00:38 smbftpd.service
lrwxrwxrwx 1 root root 31 May 29 2025 sshd.service -> /lib/systemd/system/ssh.service
-rw-r--r-- 1 root root 338 Feb 4 22:07 sync_server.service
-rw-r--r-- 1 root root 226 Feb 1 00:38 sysdiag.service
-rw-r--r-- 1 root root 246 Feb 1 00:38 sysinfo_service.service
lrwxrwxrwx 1 root root 35 Aug 8 2024 syslog.service -> /lib/systemd/system/rsyslog.service
-rw-r--r-- 1 root root 246 Feb 1 00:38 sysrestore.service
drwxr-xr-x 2 root root 4096 Jul 7 2023 systemd-resolved.service.wants
-rw-r--r-- 1 root root 305 Feb 1 00:38 system_shutdown.service
-rw-r--r-- 1 root root 220 Feb 1 00:38 system_startup.service
-rw-r--r-- 1 root root 250 Feb 1 00:38 system_umount.service
-rw-r--r-- 1 root root 398 Feb 1 00:38 trim_app_center.service
-rw-r--r-- 1 root root 213 Sep 11 2024 trim_app_cgi.service
-rw-r--r-- 1 root root 354 Sep 11 2024 trim_clean_up.service
-rw-r--r-- 1 root root 480 Feb 1 00:38 trim_connect.service
-rw-r--r-- 1 root root 245 Feb 1 00:38 trim_diskpowerd.service
-rw-r--r-- 1 root root 187 Feb 1 00:38 trim_dnsafe.service
-rw-r--r-- 1 root root 783 Jun 16 2025 trim-docs-docservice.service
-rw-r--r-- 1 root root 784 Jun 16 2025 trim-docs-fileconverter.service
-rw-r--r-- 1 root root 537 Jun 16 2025 trim-docs-pgsql.service
-rw-r--r-- 1 root root 223 Feb 1 00:38 trim_file_monitor.service
-rw-r--r-- 1 root root 215 Feb 1 00:38 trim_http_cgi.service
-rw-r--r-- 1 root root 175 Feb 1 00:38 trim_init.service
-rw-r--r-- 1 root root 370 Feb 1 00:38 trim_license.service
-rw-r--r-- 1 root root 213 Feb 1 00:38 trim_main.service
-rw-r--r-- 1 root root 276 Feb 1 00:38 trim_miniscreen.service.bak
-rw-r--r-- 1 root root 378 Feb 1 00:38 trim_nginx.service
-rw-r--r-- 1 root root 235 Feb 1 00:38 trim_raid_check.service
-rw-r--r-- 1 root root 397 Feb 1 00:38 trim_sac.service
-rw-r--r-- 1 root root 308 Feb 1 00:38 trim_sharelink.service
-rw-r--r-- 1 root root 340 Feb 1 00:38 trim_tfa.service
-rw-r--r-- 1 root root 207 Feb 1 00:38 trim_trashbind.service
-rw-r--r-- 1 root root 220 Feb 1 00:38 trim_upload.service
-rw-r--r-- 1 root root 265 Feb 1 00:38 trim_wayland.service.bak
-rw-r--r-- 1 root root 211 Feb 1 00:38 upnp.service
-rw-r--r-- 1 root root 239 Feb 1 00:38 usersrv.service
-rw-r--r-- 1 root root 306 Feb 1 00:38 webdav.service
-rw-r--r-- 1 root root 351 Feb 1 00:38 wsdd2.service
lrwxrwxrwx 1 root root 35 Dec 23 14:41 zed.service -> /lib/systemd/system/zfs-zed.service
drwxr-xr-x 2 root root 4096 Feb 4 21:41 zfs-zed.service.d
root@fnOS:/home/Andyi# cat /etc/ld.so.preload
cat: /etc/ld.so.preload: No such file or directory
root@fnOS:/home/Andyi# sudo rm -rf /var/lib/cron/.runtime
root@fnOS:/home/Andyi# sudo chattr +i /var/lib/cron/
FN-1.png

FN-2.png

收藏
送赞
分享

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

x

233

主题

1万

回帖

0

牛值

管理员

fnOS1.0上线纪念勋章

异常进程为挖矿病毒建议重装系统,我们近期排查过几例同类情况不保证清理可以没有残留
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则