I think it is fail2ban to create this folder?
Hello UFHH01,Hi romand700,
Fail2Ban does NOT create folders or files outside of its folder(s) - I wonder what's make you think, that it does.
Rename suspicious folder(s) to something like ".to-investigate" and investigate the possible files and folders ( permissions ?!? ). Have as well a look at your log - files for possible issues/errors after renaming the folder(s) and make as well a rootkit - check. Delete the folder(s) if your investigations lead nowhere.
Hello UFHH01,Hi romand700,
I have absolutely no clue, WHO or WHAT created the folder, but it sounds suspicious and I still recommend to investigate it with a rootkit checker ( en.wikipedia.org/wiki/Rootkit ) - ( "watchdog" = "rkhunter" is part of Plesk... please use it ). And please inform yourself as well about other possible ways how to secure your server ( one example is: http://kb.odin.com/en/114620 , but there are far more tutorials, documentations and suggestions for server administrators all over the internet ).
php -d open_basedir= -d safe_mode=0 plesk_password_changer.php `cat /etc/psa/.psa.shadow` --clean-up-sessions
but I have this error:
Could not open input file: plesk_password_changer.php
**Note**: The `exec` function of PHP has to be enabled, so during `plesk_password_changer.php` execution, comment the following line in `php.ini`:
disable_functions = 'apache_child_terminate, apache_setenv, define_syslog_variables, escapeshellarg, escapeshellcmd, eval, exec, ... , mysql_pconnect'
Hello UFHH01,For your "pscan2" - issue, please have a look at the link: "http://www.linuxquestions.org/quest...ver-infected-with-scanssh-pscan2-sshf-823263/" and search with Google for other suggestions and recommendations, please ( use the keyword "pscan2" - yes... with quotes, please! ).
You should consider to ask/order for some server administration support, because a compromised server can be tricky, if you are unexperienced.