✦ 运维实战教程 ✦

服务器监控一键卸载教程

阿里云、腾讯云的服务器出厂都会自带监控组件(阿里云盾 AliYunDun / 安骑士、腾讯云云监控 / 云镜)。很多用户希望对自己的服务器拥有完全的控制权,因此需要将它们卸载。本教程整理自网络经验帖,步骤清晰、命令可直接复制使用。

本页目录

  1. 卸载阿里云 ECS 服务器监控 AliYunDun
  2. 卸载腾讯云安全监控软件
  3. 轻量服务器开启 root 账户登录

1卸载阿里云 ECS 服务器监控 AliYunDun

1
首先需要到阿里云盾控制台关闭客户端:点击左侧【主机资产】,找到对应需要关闭的服务器,点击右侧的【查看】。
2
进入后把下面四项全部关闭:【客户端自保护】【网站后门连接防御】【恶意网络行为防御】【恶意主机行为防御】。

方案一:完全卸载

第一步:卸载 AliYunDun 主体

SSH 连接阿里云服务器,在终端中依次输入下方命令,进行卸载操作:

卸载 AliYunDun
wget http://update.aegis.aliyun.com/download/uninstall.sh
chmod +x uninstall.sh
./uninstall.sh
wget http://update.aegis.aliyun.com/download/quartz_uninstall.sh
chmod +x quartz_uninstall.sh
./quartz_uninstall.sh

第二步:删除 AliYunDun 残留

清理残留文件
pkill aliyun-service
rm -fr /etc/init.d/agentwatch /usr/sbin/aliyun-service
rm -rf /usr/local/aegis*

第三步:屏蔽云盾 IP

执行下面命令,通过 iptables 防火墙屏蔽云盾的 IP,让监控组件无法回连:

iptables 屏蔽云盾 IP
iptables -I INPUT -s 140.205.201.0/28 -j DROP
iptables -I INPUT -s 140.205.201.16/29 -j DROP
iptables -I INPUT -s 140.205.201.32/28 -j DROP
iptables -I INPUT -s 140.205.225.192/29 -j DROP
iptables -I INPUT -s 140.205.225.200/30 -j DROP
iptables -I INPUT -s 140.205.225.184/29 -j DROP
iptables -I INPUT -s 140.205.225.183/32 -j DROP
iptables -I INPUT -s 140.205.225.206/32 -j DROP
iptables -I INPUT -s 140.205.225.205/32 -j DROP
iptables -I INPUT -s 140.205.225.195/32 -j DROP
iptables -I INPUT -s 140.205.225.204/32 -j DROP

验证是否卸载干净

执行下面的命令查找相关进程:

验证进程
ps -ef | grep AliYunDun

或者:

验证进程(更全)
ps -aux | grep -E 'aliyun|AliYunDun'
💡 如何判断结果?没有任何内容输出,说明已经卸载干净;如果还有内容输出,说明没有卸载完(例如只显示 grep 自己那一行,属于正常现象)。

方案二:关闭 AliYunDun(保留但禁止自启)

使用 chkconfig --list 查看开机自启列表里这个软件的服务名,一般是 aegis:

查看自启服务
# chkconfig --list
aegis           0:off   1:off   2:on    3:on    4:on    5:on    6:off
agentwatch      0:off   1:off   2:on    3:on    4:on    5:on    6:off
cloudmonitor    0:off   1:off   2:on    3:on    4:on    5:on    6:off
mysql           0:off   1:off   2:off   3:off   4:off   5:off   6:off
netconsole      0:off   1:off   2:off   3:off   4:off   5:off   6:off
network         0:off   1:off   2:on    3:on    4:on    5:on    6:off

如果想开机不启动,执行 chkconfig --del aegis(这个 aegis 就是查出来的 AliYunDun 后台服务名):

停止并删除服务
service aegis stop  # 停止服务
chkconfig --del aegis  # 删除服务

如果还有残留进程,可通过以下命令强制结束:

结束残留进程
ps -ef | grep -v grep | grep -i aliyundun | awk '{print $2}' | xargs kill -9

2卸载腾讯云安全监控软件

腾讯云服务器默认安装的监控组件包括:云监控(安装目录 /usr/local/qcloud/stargate 和 /usr/local/qcloud/monitor)和主机安全(云镜)(安装目录 /usr/local/qcloud/YunJing)。新开的服务器如果不取消勾选,都会默认安装。

方式一:输入命令卸载

在终端中依次执行以下三个卸载脚本:

卸载云监控与云镜
/usr/local/qcloud/stargate/admin/uninstall.sh
/usr/local/qcloud/YunJing/uninst.sh
/usr/local/qcloud/monitor/barad/admin/uninstall.sh

脚本卸载完监控后,腾讯云目录里可能还残留其他组件。为了保险起见,停用并删除 TAT 组件(自动化助手)与整个 qcloud 目录:

清理 qcloud 残留
systemctl stop tat_agent
systemctl disable tat_agent
rm -f /etc/systemd/system/tat_agent.service
rm -fr /usr/local/qcloud

方式二:使用打包好的 Shell 脚本一键卸载

以下两个脚本都可以用,第二个国内网络可访问:

一键卸载(脚本 1)
wget -qO- https://raw.githubusercontent.com/littleplus/TencentAgentRemove/master/remove.sh | bash
一键卸载(脚本 2,国内可用)
wget -qO- https://cdn.jsdelivr.net/gh/lufei/TencentAgentRemove@master/remove.sh | bash

验证是否卸载完成

执行下面的命令检查残留:

验证 agent 进程
ps -A | grep agent
⚠️ 无任何输出说明已经卸载完成;如果有输出,请确认是不是你自己的程序。卸载完成后记得重启服务器。

3轻量服务器开启 root 账户登录

轻量应用服务器默认使用 ubuntu 等普通账户登录,需要切换到 root 账户操作。

方案一:按步骤手动开启

1
使用 ubuntu 账户登录轻量应用服务器,执行以下命令设置 root 密码:
设置 root 密码
sudo passwd root

输入 root 的密码后按 Enter,重复输入一次再按 Enter。返回下面信息即表示设置成功:

成功提示
passwd: password updated successfully
2
执行以下命令打开 SSH 配置文件:
编辑 sshd_config
sudo vi /etc/ssh/sshd_config
3
按 i 进入编辑模式,找到 #Authentication,将 PermitRootLogin 参数修改为 yes;如果该参数被注释,请先去掉首行的注释符号(#)。
4
按 Esc,输入 :wq 保存退出,然后执行以下命令重启 SSH 服务:
重启 SSH 服务
sudo service ssh restart
5
切换到 root,输入刚才设置的密码进入:
切换 root
su root

方案二:一键开启

一键开启 root(示例)
sudo -i
echo root:77nn.net |chpasswd root
sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin yes/g' /etc/ssh/sshd_config;
sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication yes/g' /etc/ssh/sshd_config;
service sshd restart
🚨 重要提醒:上面脚本示例中的默认密码是 77nn.net,登录后一定要马上修改密码!修改命令:passwd
📌 本页教程内容整理自网络公开资料(原文出处),仅供学习交流。操作服务器命令有一定风险,建议先在测试环境验证,重要数据请提前备份。