Clean Malware on Hostinger VPS
Budget: $10 – $30 CAD
My Hostinger VPS was automatically shut down after malware activity was detected. It runs on Linux and already has basic antivirus software in place, yet something slipped through. I have not been able to pinpoint any suspicious files or processes so far, so the machine will need a full forensic sweep before it is brought back online.
Here’s what I need, step-by-step:
• Power the VPS up safely through hPanel or SSH rescue mode and capture a snapshot for analysis.
• Audit every running service, scheduled task, and startup script, identifying and terminating malicious or unnecessary processes.
• Locate, isolate, and delete infected files or code injections (web roots, crontabs, tmp folders, hidden binaries, etc.).
• Patch vulnerabilities and harden the system—e.g., kernel and package updates, SSH hardening, iptables/ufw rules, fail2ban, and any other Best-Practice measures you recommend.
• Confirm the existing antivirus is correctly configured; reinforce it with complementary tools such as ClamAV, rkhunter, or Maldet if appropriate.
• Deliver a concise remediation report showing what was found, what was removed, and which preventive steps were applied.
Acceptance criteria
1. VPS boots without triggering Hostinger’s automated abuse shutdown.
2. No malicious processes or files detected by repeat scans (ClamAV + rkhunter).
3. Security hardening steps documented and reproducible.
Root SSH access will be provided immediately after award.
Here’s what I need, step-by-step:
• Power the VPS up safely through hPanel or SSH rescue mode and capture a snapshot for analysis.
• Audit every running service, scheduled task, and startup script, identifying and terminating malicious or unnecessary processes.
• Locate, isolate, and delete infected files or code injections (web roots, crontabs, tmp folders, hidden binaries, etc.).
• Patch vulnerabilities and harden the system—e.g., kernel and package updates, SSH hardening, iptables/ufw rules, fail2ban, and any other Best-Practice measures you recommend.
• Confirm the existing antivirus is correctly configured; reinforce it with complementary tools such as ClamAV, rkhunter, or Maldet if appropriate.
• Deliver a concise remediation report showing what was found, what was removed, and which preventive steps were applied.
Acceptance criteria
1. VPS boots without triggering Hostinger’s automated abuse shutdown.
2. No malicious processes or files detected by repeat scans (ClamAV + rkhunter).
3. Security hardening steps documented and reproducible.
Root SSH access will be provided immediately after award.
Related categories:
Linux
Web Security
Computer Security
VPS
Internet Security
System Administration