Frank - Are you not running CSF on these servers? The current CSF version detects the issue and emails you an alert.Well, AVG is now detecting this rootkit, so if you run AVG on these servers and scan your lib and/or lib64 directories, you should detect the ones with the exploit. Make sure not to connect from one server to another because you will cross-contaminate your clean servers.
I'd suggest posting on the WHT thread re: a more automated way of checking. I know that CloudLinux also posted a detection script.