Commit e1e17938 by ChongmingDu

挖空病毒处理

parent d48f617d
1. 检查动态链库,是否有异常lib
1. 检查动态链库,是否有异常lib
- echo LD_PRELOAD
- 查看/etc/ld.so.preload
2. 查看定时任务
- crontab -l
- cat /var/spool/cron/
3. killall kworkerds
#shell script
```
echo "" > /etc/ld.so.preload
chattr +i /etc
rm -rf /var/spool/cron/*
rm -rf /etc/cron.d/*
chattr +i /var/spool/cron/
rm -f /usr/local/lib/*
chattr +i /usr/local/lib
killall kworkerds
rm -f /var/tmp/kworkerds*
rm -f /var/tmp/1.so
rm -f /tmp/kworkerds*
rm -f /tmp/1.so
rm -f /var/tmp/wc.conf
rm -f tmp/wc.conf
```
[ 详细 ](https://blog.csdn.net/xinxin_2011/article/details/85047245)
\ No newline at end of file
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment