Ok more info. I had already deleted the file xxxx but I still tried:
Code: Select all
lsof | grep "/mnt/HDA_ROOT/"
cc3-fastc 2068 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2070 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2071 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2074 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2075 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2077 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2078 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2084 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2085 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2086 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2087 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 2088 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 3125 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 10733 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
cc3-fastc 2068 12877 admin 4u REG 9,9 61440 7302 /mnt/HDA_ROOT/.config/cloudconnector/CloudConnector3/config.db
python 8729 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8729 8730 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8729 8731 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8729 8732 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8729 8733 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8729 8734 admin 16w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 8784 admin 9w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
dhcpd 11784 admin 3w REG 9,9 877080 13305 /mnt/HDA_ROOT/.logs/network/bootup.log
dhcpd 11784 admin 7w REG 9,9 280 7449 /mnt/HDA_ROOT/.config/dhcp/dhcpd_docker0.leases
dhcpd 11787 admin 3w REG 9,9 877080 13305 /mnt/HDA_ROOT/.logs/network/bootup.log
dhcpd 11787 admin 7w REG 9,9 274 7248 /mnt/HDA_ROOT/.config/dhcp/dhcpd_lxcbr0.leases
dhclient 12148 admin 5w REG 9,9 1010 7418 /mnt/HDA_ROOT/.config/dhclient/br0.leases
python 13069 admin 8w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 13069 13146 admin 8w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 13069 13148 admin 8w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
python 13069 13150 admin 8w REG 9,9 961101 13340 /mnt/HDA_ROOT/.logs/nvs_event.log
proftpd 17044 guest 4r REG 9,9 72 7296 /mnt/HDA_ROOT/.config/group
qulogdb 17416 admin cwd DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 admin 3uW REG 9,9 52 7363 /mnt/HDA_ROOT/.config/qulog/db/aria_log_control
qulogdb 17416 admin 4r DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 admin 5u REG 9,9 24576 7379 /mnt/HDA_ROOT/.config/qulog/db/aria_log.00000001
qulogdb 17416 admin 8u REG 9,9 4096 7383 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYI
qulogdb 17416 admin 9u REG 9,9 154140 7387 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYD
qulogdb 17416 admin 10u REG 9,9 2048 7453 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYI
qulogdb 17416 admin 13u REG 9,9 0 7231 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYD
qulogdb 17416 17420 admin cwd DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17420 admin 3uW REG 9,9 52 7363 /mnt/HDA_ROOT/.config/qulog/db/aria_log_control
qulogdb 17416 17420 admin 4r DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17420 admin 5u REG 9,9 24576 7379 /mnt/HDA_ROOT/.config/qulog/db/aria_log.00000001
qulogdb 17416 17420 admin 8u REG 9,9 4096 7383 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYI
qulogdb 17416 17420 admin 9u REG 9,9 154140 7387 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYD
qulogdb 17416 17420 admin 10u REG 9,9 2048 7453 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYI
qulogdb 17416 17420 admin 13u REG 9,9 0 7231 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYD
qulogdb 17416 17441 admin cwd DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17441 admin 3uW REG 9,9 52 7363 /mnt/HDA_ROOT/.config/qulog/db/aria_log_control
qulogdb 17416 17441 admin 4r DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17441 admin 5u REG 9,9 24576 7379 /mnt/HDA_ROOT/.config/qulog/db/aria_log.00000001
qulogdb 17416 17441 admin 8u REG 9,9 4096 7383 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYI
qulogdb 17416 17441 admin 9u REG 9,9 154140 7387 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYD
qulogdb 17416 17441 admin 10u REG 9,9 2048 7453 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYI
qulogdb 17416 17441 admin 13u REG 9,9 0 7231 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYD
qulogdb 17416 17442 admin cwd DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17442 admin 3uW REG 9,9 52 7363 /mnt/HDA_ROOT/.config/qulog/db/aria_log_control
qulogdb 17416 17442 admin 4r DIR 9,9 4096 7290 /mnt/HDA_ROOT/.config/qulog/db
qulogdb 17416 17442 admin 5u REG 9,9 24576 7379 /mnt/HDA_ROOT/.config/qulog/db/aria_log.00000001
qulogdb 17416 17442 admin 8u REG 9,9 4096 7383 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYI
qulogdb 17416 17442 admin 9u REG 9,9 154140 7387 /mnt/HDA_ROOT/.config/qulog/db/mysql/proc.MYD
qulogdb 17416 17442 admin 10u REG 9,9 2048 7453 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYI
qulogdb 17416 17442 admin 13u REG 9,9 0 7231 /mnt/HDA_ROOT/.config/qulog/db/qulog/access_filter.MYD
winbindd 19265 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
winbindd 19265 admin 8u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
ncdb 19480 admin cwd DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 admin 3uW REG 9,9 52 7050 /mnt/HDA_ROOT/.config/nc/db/aria_log_control
ncdb 19480 admin 4r DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 admin 5u REG 9,9 24576 7051 /mnt/HDA_ROOT/.config/nc/db/aria_log.00000001
ncdb 19480 admin 8u REG 9,9 1024 7157 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYI
ncdb 19480 admin 9u REG 9,9 1024 7151 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYI
ncdb 19480 admin 10u REG 9,9 0 7343 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYD
ncdb 19480 admin 12u REG 9,9 2048 7172 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYI
ncdb 19480 admin 13u REG 9,9 0 7526 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYD
ncdb 19480 admin 15u REG 9,9 0 7518 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYD
ncdb 19480 admin 18u REG 9,9 2048 7190 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYI
ncdb 19480 admin 19u REG 9,9 0 7473 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYD
ncdb 19480 19492 admin cwd DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19492 admin 3uW REG 9,9 52 7050 /mnt/HDA_ROOT/.config/nc/db/aria_log_control
ncdb 19480 19492 admin 4r DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19492 admin 5u REG 9,9 24576 7051 /mnt/HDA_ROOT/.config/nc/db/aria_log.00000001
ncdb 19480 19492 admin 8u REG 9,9 1024 7157 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYI
ncdb 19480 19492 admin 9u REG 9,9 1024 7151 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYI
ncdb 19480 19492 admin 10u REG 9,9 0 7343 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYD
ncdb 19480 19492 admin 12u REG 9,9 2048 7172 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYI
ncdb 19480 19492 admin 13u REG 9,9 0 7526 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYD
ncdb 19480 19492 admin 15u REG 9,9 0 7518 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYD
ncdb 19480 19492 admin 18u REG 9,9 2048 7190 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYI
ncdb 19480 19492 admin 19u REG 9,9 0 7473 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYD
ncdb 19480 19539 admin cwd DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19539 admin 3uW REG 9,9 52 7050 /mnt/HDA_ROOT/.config/nc/db/aria_log_control
ncdb 19480 19539 admin 4r DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19539 admin 5u REG 9,9 24576 7051 /mnt/HDA_ROOT/.config/nc/db/aria_log.00000001
ncdb 19480 19539 admin 8u REG 9,9 1024 7157 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYI
ncdb 19480 19539 admin 9u REG 9,9 1024 7151 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYI
ncdb 19480 19539 admin 10u REG 9,9 0 7343 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYD
ncdb 19480 19539 admin 12u REG 9,9 2048 7172 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYI
ncdb 19480 19539 admin 13u REG 9,9 0 7526 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYD
ncdb 19480 19539 admin 15u REG 9,9 0 7518 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYD
ncdb 19480 19539 admin 18u REG 9,9 2048 7190 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYI
ncdb 19480 19539 admin 19u REG 9,9 0 7473 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYD
ncdb 19480 19540 admin cwd DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19540 admin 3uW REG 9,9 52 7050 /mnt/HDA_ROOT/.config/nc/db/aria_log_control
ncdb 19480 19540 admin 4r DIR 9,9 4096 7047 /mnt/HDA_ROOT/.config/nc/db
ncdb 19480 19540 admin 5u REG 9,9 24576 7051 /mnt/HDA_ROOT/.config/nc/db/aria_log.00000001
ncdb 19480 19540 admin 8u REG 9,9 1024 7157 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYI
ncdb 19480 19540 admin 9u REG 9,9 1024 7151 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYI
ncdb 19480 19540 admin 10u REG 9,9 0 7343 /mnt/HDA_ROOT/.config/nc/db/nc/sender.MYD
ncdb 19480 19540 admin 12u REG 9,9 2048 7172 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYI
ncdb 19480 19540 admin 13u REG 9,9 0 7526 /mnt/HDA_ROOT/.config/nc/db/nc/policy_categories.MYD
ncdb 19480 19540 admin 15u REG 9,9 0 7518 /mnt/HDA_ROOT/.config/nc/db/nc/receiver.MYD
ncdb 19480 19540 admin 18u REG 9,9 2048 7190 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYI
ncdb 19480 19540 admin 19u REG 9,9 0 7473 /mnt/HDA_ROOT/.config/nc/db/nc/policy.MYD
winbindd 19494 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
winbindd 19494 admin 8u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd 19521 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd 19521 admin 3u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd-noti 19525 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd-noti 19525 admin 3u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
cleanupd 19526 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
cleanupd 19526 admin 3u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
winbindd 19527 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
winbindd 19527 admin 8u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd 22813 admin mem REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
smbd 22813 admin 3u REG 9,9 430080 6646 /mnt/HDA_ROOT/.config/secrets.tdb
rsyslogd 25312 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
rsyslogd 25312 25313 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
rsyslogd 25312 25314 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
rsyslogd 25312 25315 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
rsyslogd 25312 25316 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
rsyslogd 25312 25317 admin 5w REG 9,9 1040151 13285 /mnt/HDA_ROOT/.logs/kmsg
qdesk_sol 28449 admin cwd DIR 9,9 4096 17 /mnt/HDA_ROOT/update_pkg/helpdesk
qdesk_sol 28449 admin 255r REG 9,9 287 154 /mnt/HDA_ROOT/update_pkg/helpdesk/diagnostic_tool/qdesk_soldier
In addition the index.html was replaced back with the ransomware one, I had to move back index.html.bak again. So either I didn't put if off internet correcly, or it have some form a cron or process scheduled.