Linux · VPS · cPanel · aaPanel · Plesk

Linux server malware removal and backdoor cleanup

I investigate compromised Linux servers, VPS and hosting environments for suspicious processes, miners, outbound spam, phishing files, web shells, cron jobs, systemd services, users and SSH keys. The goal is to identify the entry path and persistence, not merely delete one detected file.

Do not reboot or delete files blindly. Preserve a snapshot, logs and the current state first, otherwise useful evidence may be lost and the entry point becomes harder to identify.

When the server needs an incident review

A single symptom is not proof of compromise, but several signs together call for prompt investigation.

High resource usage

CPU stays busy with an unknown process, the server becomes unusually slow or the load suddenly rises.

Spam and blacklists

The IP sends mail, abuse notices arrive, SMTP is blocked or domains appear on blacklists.

Recurring infections

Websites become infected again after a file cleanup or backup restoration.

Unknown persistence

New cron jobs, systemd services, users, SSH keys or executables in temporary directories appear.

Phishing and redirects

Foreign pages, casino redirects, doorway pages or malicious downloads are hosted on the server.

Hosting suspension

The provider restricts the server due to abuse, outbound traffic or infected files.

How Linux/VPS cleanup works

01

Preserve the state

Record symptoms, back up available data and retain relevant logs.

02

Investigate

Review processes, connections, users, SSH, cron, systemd, web roots, databases and recent changes.

03

Find the entry path

Check vulnerable CMS components and panels, stolen credentials, exposed services and exploit traces.

04

Contain and clean

Stop malicious processes, isolate files, remove persistence and restore required components.

05

Close the cause

Rotate compromised credentials, update software and apply the necessary hardening.

06

Verify

Test sites and services, outbound connections, resource use and whether indicators return.

What the result includes

  • List of identified indicators and affected components
  • Cleanup of malicious files, jobs and processes within the agreed scope
  • Review of hosted websites when they are part of the incident
  • Closure of the identified entry path or a clear clean-migration plan
  • Critical credential rotation and guidance for SSH, firewall, backups and updates
  • Short report covering findings, changes and follow-up monitoring

When a clean rebuild is safer

If an attacker obtained root access or system-file integrity cannot be established, promising a reliable manual cleanup would be misleading. In that case I recommend provisioning a clean server, migrating verified data and switching traffic only after validation.

Frequently asked questions

How is server cleanup different from website malware removal?

Website cleanup focuses on CMS files and the database. A server incident also requires reviewing processes, users, SSH keys, cron, systemd, network connections and other sites in the same environment.

Can a VPS be cleaned without reinstalling it?

Sometimes, when the compromise is limited to a site or one user. With root compromise, a clean rebuild and verified data migration is safer.

What access is required?

Usually SSH with sufficient permissions, the control panel and hosting information. Access is shared privately and rotated after the work.

How long does it take?

I provide scope and timing after the initial review. A limited incident may take several hours; multiple infected sites or system-level persistence takes longer.

Can you guarantee it will never be hacked again?

No one can honestly guarantee that. I remove identified persistence, close the discovered entry path and provide concrete monitoring and hardening steps.

Incident review

Describe what is happening on the server

Include the Linux distribution or panel, symptoms, number of sites and any hosting warning. Do not send passwords in the form.

Related services

Telegram