1、释放文件:
C:\WINDOWS\avantage32.exe
2、修改注册表:
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\DmapimK
@="iLcITXweXrqbgmppqUbQykLcR"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\HwPaqncy
@="YYqqqZtt^~@K|J@"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\InprocServer32
@="C:\\WINDOWS\\system32\\scrobj.dll"
"ThreadingModel"="Apartment"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\IuMkS
@="WpvfZEOjkPRj}AqgRhMIcLwsFQtx"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\lpkjVc
@="LUT~yipnN}yrA^pBz^VguT"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\LptpSt
@="T]VZ|OJRWw|ohLkAEQq|Kw"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\ProgID
@="Scriptlet.HostEncode"
HKEY_CLASSES_ROOT\CLSID\{7C231048-7C23-1048-7C23-10487C231048}\yofcrdZro
@="^YJHFvcpT[eMAaO]JN@q[\\xd"
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
"{07C231048FFFFFFFF}"=hex:56,3e,a8,0e,0b,a2,a7,a6,41,06,53,98,d8,b9,44,a3,38,32,91,6e,d8,\
b6,05,a1,99,e8,09,9b,1f,b1,5a,23,9d,e9,e0,29,a4,c8,ac,79,17,a3,\
e6,5b,90,e7,96,79,87,f4,5c,4f,27,85,42,a6,a0,37,8a,7b,62,2c,ac,\
15,16,96,2e,7d,2b,bd,d1,2d,8e,14,01,a8,5f,5d,71,8f,e2,06,d1,8e,\
98,a7,0c,c1,44,6b,7f,2b,e4,9c,b6,59,68,a7,c2,cb,c1,8b,cb,bb,05
"{I7C231048FFFFFFFF}"=hex:06,00,00,00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Melt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters
"TrapPollTimeMilliSecs"=dword:00003a98
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Avantage
"ImagePath"="C:\WINDOWS\avantage32.exe"
3、自动访问网络。
4、处理流程:
(1)结束进程avantage32.exe
(2)删除C:\WINDOWS\avantage32.exe
(3)删除上述注册表项