I have a process consuming 99% of my droplet's CPU called phpv4gWoI_xguep and phpadYGh4_xguep

Posted January 15, 2018 1.5k views
UbuntuApacheLAMP Stack

I could not find anything related to that processes: phpv4gWoIxguep or phpadYGh4xguep
I noticed this because I created an alert of CPU running high.

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Submit an Answer
1 answer

The reason you could not find anything is because these are automatically generated process names. This activity indicates that your droplet has been compromised and is running malware either to attack other servers or to use your resources to mine cryptocurrency.

Your best course of action is to download your files and configuration (being sure to check them for anything unusual) and migrate your services to a clean server.