禁用如下服务:
[HX massacre / HXmassacre]
<E:\WINDOWS\help\HXpass.exe><N/A>
[Network System / Universal Disk Manager]
<E:\Program Files\Common Files\SAND\Network.exe><N/A>
进入注册表
删除
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<advapi32><; RUNDLL32 E:\WINDOWS\Downlo~1\_IS_0518\_IS_ISC.DLL,isc>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<hzs><; c:\Program Files\meibu\watchhzs.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ISC><; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ISC_UpDate><; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MoveSearch><; E:\Program Files\wsearch\Search.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MyIMLite><; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MyIMLite_UpDate><; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NicChina><; [Program Files]\nicchina.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<PigLocalSearch><; f:\Program Files\网络猪\PigStart.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<inetsvr><E:\Program Files\ieup\inetsvr.exe>
卸载
c:\Program Files\meibu
f:\Program Files\网络猪
E:\Program Files\ieup
E:\Program Files\wsearch
Program Files]\nicchina.exe
删除
c:\Program Files\meibu
f:\Program Files\网络猪
E:\Program Files\ieup
E:\Program Files\wsearch
Program Files\nicchina
E:\WINDOWS\help\HXpass.exe
E:\Program Files\Common Files\SAND
E:\WINDOWS\Downlo~1\_IS_0518\_IS_ISC.DLL
MyIMLite文件夹
找不到文件或无法删除请参考http://www.xfilt.com/tech/trojan-horse.htm