阿里云【kthreaddk】挖矿病毒清理

top看出进程

查出关联进程

[root@test-server 7441]# systemctl status 7441
● session-471546.scope - Session 471546 of user root
   Loaded: loaded (/run/systemd/system/session-471546.scope; static; vendor preset: disabled)
  Drop-In: /run/systemd/system/session-471546.scope.d
           └─50-After-systemd-logind\x2eservice.conf, 50-After-systemd-user-sessions\x2eservice.conf, 50-Description.conf, 50-SendSIGHUP.conf, 50-Slice.conf, 50-TasksMax.conf
   Active: active (abandoned) since Thu 2023-03-16 09:42:30 CST; 4 days ago
   CGroup: /user.slice/user-0.slice/session-471546.scope
           ├─4163 283b24
           └─7441 kthreaddk

kill 掉两个进程

kill -9 4163
kill -9 7441 

清空crontab

crontab -r

重启系统

posted @ 2023-03-20 11:45  西门运维  阅读(313)  评论(0编辑  收藏  举报