found the server was black, decisively put IP to the ban,
but the process of finding black me has been in Sleeping , with what Kill , Pkill It doesn't work .
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6E/AA/wKioL1WCbdPz-rWaAAJ6xAeXTCI069.jpg "title=" a.jpg " alt= "Wkiol1wcbdpz-rwaaaj6xaextci069.jpg"/>
[email protected]:/proc# ps -ef|grep zlroot 22229 1 0 19:19 ? 00:00:00 sh -c (chmod -r 777 /tmp) ; (rm -f /tmp/.lz*) ; ( echo yes|cp -p /etc/.zl /tmp/.lz1429615177) root 22232 22229 0 19:19 ? 00:00:00 sh -c (chmod -r 777 /tmp) ; (rm -f /tmp/.lz*) ; (echoyes|cp -p /etc/.zl /tmp/.lz1429615177) root 22234 22232 0 19:19 ? 00:00:00 cp -p /etc/.zl /tmp/. lz1429615177root 28406 16879 0 20:14 pts/3 00:00:00 grep --color=auto zl
in proc see
[Email protected]:/proc# cat /proc/22229/statusname: shstate: s (sleeping) tgid: 22229pid: 22229ppid: 1tracerpid : 0uid: 0 0 0 0Gid: 0 0 0 0FDSize: 64Groups: 0VmPeak: 4400 kbvmsize: 4400 kbvmlck: 0 kBVmPin: 0 kBVmHWM: 604 kBVmRSS: 604 kBVmData: 188 kbvmstk: 136 kbvmexe: 104 kBVmLib: 1884 kBVmPTE: 28 kBVmSwap: 0 kBThreads:        1SIGQ:   2/15879SIGPND: 0000000000000000SHDPND: 0000000000000000SigBlk: 0000000000000004SigIgn: 0000000000001007SigCgt: 0000000000010000CAPINH: 0000000000000000CAPPRM: FFFFFFFFFFFFFFFFCAPEFF: FFFFFFFFFFFFFFFFCAPBND: ffffffffffffffffCpus_allowed: 7fffCpus_allowed_list: 0-14Mems_allowed: 00000000,00000001Mems_allowed_list: 0voluntary_ctxt_switches: 3nonvoluntary_ctxt_switches: 0
This process is directly removed try
#rm /proc/22229rm: cannot remove ' 22229/task/22229/syscall ': permission deniedrm: cannot remove ' 22229/task/22229/cmdline ': permission deniedrm: cannot remove ' 22229/task/22229/stat ': permission deniedrm: cannot remove ' 22229/task/22229/statm ': Permission deniedrm: cannot remove ' 22229/task/22229/maps ': permission deniedrm: Cannot remove ' 22229/task/22229/numa_maps ': permission deniedrm: cannot remove ' 22229/ Task/22229/mem ': permission deniedrm: cannot remove ' 22229/task/22229/cwd ': Permission deniedrm: cannot remove ' 22229/task/22229/root ': permission deniedrm: cannot remove ' 22229/task/22229/exe ': permission deniedrm: cannot remove ' 22229/task/22229/ Mounts ': permission deniedrm: cannot remove ' 22229/task/22229/mountinfo ': Permission deniedrm: cannot&Nbsp;remove ' 22229/task/22229/clear_refs ': permission deniedrm: cannot remove ' 22229/task/ 22229/smaps ': permission deniedrm: cannot remove ' 22229/task/22229/pagemap ': Permission deniedrm: cannot remove ' 22229/task/22229/attr/current ': Operation not permittedrm: cannot remove ' 22229/task/22229/attr/prev ': operation not Permittedrm: cannot remove ' 22229/task/22229/attr/exec ': operation not permittedrm: cannot remove ' 22229/task/22229/attr/fscreate ':operation not permittedrm: Cannot remove ' 22229/task/22229/attr/keycreate ': operation not permittedrm: cannot remove ' 22229/task/22229/attr/sockcreate ': operation not permittedrm: cannot Remove ' 22229/task/22229/wchan ': permission deniedrm: cannot remove ' 22229/task/22229/stack ' : permission deniedrm: cannot Remove ' 22229/task/22229/schedstat ': permission deniedrm: cannot remove ' 22229/task/22229/ Latency ': permission deniedrm: cannot remove ' 22229/task/22229/cpuset ': Permission deniedrm: cannot remove ' 22229/task/22229/cgroup ': permission deniedrm: cannot remove ' 22229/task/22229/oom_score ': permission deniedrm: cannot remove ' 22229/task/ 22229/oom_adj ': permission deniedrm: cannot remove ' 22229/task/22229/oom_score_adj ': Permission deniedrm: cannot remove ' 22229/task/22229/loginuid ': permission deniedrm: cannot remove ' 22229/task/22229/sessionid ': permission deniedrm: cannot remove ' 22229/task/22229/io ': permission deniedrm: cannot remove ' 22229/fd/0 ':Operation not permittedrm: cannot remove ' 22229/FD/1 ':operation not permittedrm: cannot remove ' 22229/fd/2 ':operation not permittedrm: cannot remove ' 22229/FD/3 ': Operation not permittedrm: cannot remove ' 22229/FD/4 ': operation not permittedrm: cannot remove ' 22229/fdinfo/0 ': Operation not permittedrm: cannot remove ' 22229/FDINFO/1 ': operation not permittedrm: cannot remove ' 22229/FDINFO/2 ': Operation not permittedrm: cannot remove ' 22229/FDINFO/3 ': operation not permittedrm: Cannot remove ' 22229/FDINFO/4 ': operation not permittedrm: cannot remove ' 22229/ns/net ':operation not permittedrm: cannot remove ' 22229/ns/uts ':Operation not permittedrm: cannot remove ' 22229/NS/IPC ':operation not permittedrm: Cannot remove ' 22229/net/ip_tables_targets ': operation not permittedrm: cannot Remove ' 22229/net/ip_tableS_matches ': operation not permittedrm: cannot remove ' 22229/net/ip_tables_names ': operation not permittedrm: cannot remove ' 22229/net/ip6_tables_targets ': operation not permittedrm: cannot remove ' 22229/net/ip6_tables_matches ': Operation not permittedrm: cannot remove ' 22229/net/ip6_tables_names ': Operation not Permittedrm: cannot remove ' 22229/net/packet ': operation not permittedrm: cannot remove ' 22229/net/ip6_flowlabel ': operation not permittedrm: cannot remove ' 22229 /net/rt6_stats ': operation not permittedrm: cannot remove ' 22229/net/ipv6_route ': operation not permittedrm: cannot remove ' 22229/net/if_inet6 ': Operation Not permittedrm: cannot remove ' 22229/net/dev_snmp6/eth1 ': operation not Permittedrm: cannot remove ' 22229/net/dev_snmp6/eth0 ': operation not permittedrm: cannot remove ' 22229/net/dev_snmp6/lo ': operation not permittedrm: cannot remove ' 22229/net/snmp6 ': Operation not permittedrm: cannot remove ' 22229/net/sockstat6 ': operation not permittedrm: cannot remove ' 22229/net/udplite6 ': operation not permittedrm: cannot Remove ' 22229/net/raw6 ': operation not permitted
It's still not working.
later find, find, related information finally found Kill-kill
Kill-kill ProcessID
It's invincible.
Kill-kill 22229
The discovery was finally taken, and the command was powerful.
Linux Invincible Kill-kill ProcessID