major way to detect malware first top and see if any process use lot of cpu 1, cat /proc/pid/pwd to see which dir it run in and see any suspicious files in it