我的互联网体验非常慢。在vnstat我看到了
rx: 4 kbit/s 3 p/s tx: 94.74 Mbit/s 14072 p/s^C
eth4 / traffic statistics
rx | tx
--------------------------------------+------------------
bytes 11.85 MiB | 30.30 GiB
--------------------------------------+------------------
max 6.86 Mbit/s | 94.93 Mbit/s
average 28.18 kbit/s | 73.80 Mbit/s
min 0 kbit/s | 0 kbit/s
--------------------------------------+------------------
packets 17127 | 37761168
--------------------------------------+------------------
max 584 p/s | 14108 p/s
average 4 p/s | 10964 p/s
min 0 p/s | 0 p/s
--------------------------------------+------------------
time 57.40 minutes
我看到使用nethogs,
PID USER PROGRAM DEV SENT RECEIVED
2546 root su eth4 0.013 0.072 KB/sec
? root 192.168.7.100:58888-43.250.83.106:61878 0.021 0.025 KB/sec
? root 192.168.7.100:58888-70.24.39.90:65025 0.021 0.025 KB/sec
? root 192.168.7.100:44145-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:52239-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:15834-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:29433-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:49576-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:36540-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:32289-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:25437-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:10155-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:32125-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:59269-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:57686-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:2747-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:59482-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:58985-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:56246-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:4345-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:10665-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:40676-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:35600-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:12241-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:43541-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:19124-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:1676-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:37809-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:7017-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:14998-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:64834-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:31544-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:17969-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:57675-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:32002-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:1233-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:64445-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:51733-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:38604-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:63299-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:96-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:28078-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:40611-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:4304-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:43318-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:8573-115.28.112.60:7575 0.168 0.000 KB/sec
? root 192.168.7.100:51347-115.28.112.60:7575 0.168 0.000 KB/sec
似乎有人运行了一个torrent应用程序并从我的电脑上传了所有内容。不过不确定。
我怎么知道这个令人讨厌的东西是什么过程?我需要停止并防止它在将来发生。
我被典当了吗?
更新
我已经通过我的路由器防火墙关闭了除sshd(22)之外的所有端口。现在我没有看到这个过程。但是现在nethogs显示出这种奇怪的输出。
PID USER PROGRAMDEV SENT RECEIVED
? root unknown TCP 0.000 0.000 KB/sec
netstat没有显示任何pid!
—
Shiplu Mokaddim
我提到的命令。我仔细检查了一下。它确实显示了它。
—
Firelord
@Firelord没有ip的条目
—
Shiplu Mokaddim
115.28.112.60
在输出中 netstat -natup
我不确定nethogs究竟是如何工作的,但这个问号是不是意味着它是一个“过去”的联系?如果该过程不再存在,则nethogs将显示一个问号。缺乏
—
Rik
115.28.112.60
在 netstat -natup
似乎表明了这一点。你现在还有奇怪的联系吗?也许张贴了 netstat -natup
-result或/甚至是 ps aux
看看是否有一个奇怪的进程在运行,你无法识别。
netstat -natup
显示。