1.替换C:\WINDOWS\system32\userinit.exe
2.删除注册表
<{B61C60B5-D82D-83D8-94EA-3E83D72C72C7}><C:\WINDOWS\system32\BOREG.dll>
<{1B50A5F9-2C61-D71C-F93E-82C71C71C60B}><C:\WINDOWS\system32\LNPCE.dll>
<{F93E83D7-0A4F-B5FA-D71C-60A50B5FA4E9}><C:\WINDOWS\system32\ZBDQS.dll>
<{E82D72C6-F93E-A4EA-C60B-5F94FA4E93D8}><C:\WINDOWS\system32\MOQDF.dll>
<{D71C61B6-E82E-93E9-B5FA-4E84E93D82C7}><C:\WINDOWS\system32\NPREG.dll>
<{C60B50A5-D72D-82D8-A4E9-3D83D82C71B6}><C:\WINDOWS\system32\OQSFH.dll>
<{A4E93E93-B60B-61B6-82C7-1C61B60A5F94}><C:\WINDOWS\system32\CEGTV.dll>
<{93D82E82-A5FA-60A5-71B6-0B50A5F94E84}><C:\WINDOWS\system32\DFHUW.dll>
<{82C72D71-A4E9-5F94-60A5-0A4F94E83D83}><C:\WINDOWS\system32\KMOBE.dll>
<{0A4F94E8-1B50-C60B-E82D-71B60C60B5FA}><C:\WINDOWS\system32\SUWJL.dll>
<{B5FA4FA4-C61C-72C7-93D8-2C72C71B60A5}><C:\WINDOWS\system32\VXZMO.dll>
<{71B61C60-93D8-4E83-5F94-F93E83D72C72}><C:\WINDOWS\system32\RTVIL.dll>
<{60A60B5F-82C7-3D72-4E83-E82D72C61C61}><C:\WINDOWS\system32\YACQS.dll>
<{5FA5FA4E-71B6-2C61-3D73-D71C61B50B50}><C:\WINDOWS\system32\RTWJL.dll>
<{4E94E93D-60A5-1B50-2C72-C60B50A40A4F}><C:\WINDOWS\system32\YADQS.dll>
<{3E83D82C-5F94-0A4F-1B61-B5FA4F94F93E}><C:\WINDOWS\system32\FIKXZ.dll>
<{2C61B60A-3D72-E82D-FA4F-93D82D82D71C}><C:\WINDOWS\system32\ACERT.dll>
<{D71C60B6-E82E-93E9-B5FA-4E84E83D82C7}><C:\WINDOWS\system32\ZBDQS.dll>
<{C60B5FA5-D72D-82D8-A4E9-3D83D72C71B6}><C:\WINDOWS\system32\GIKXZ.dll>
<{B5FA4EA4-C61C-72C7-93D8-2C72C61B60A5}><C:\WINDOWS\system32\NPREG.dll>
<{A4E93E93-B60B-61B6-82C7-1C61B50A5F94}><C:\WINDOWS\system32\UWYLN.dll>
<{93D82D82-A5FA-60A5-71B6-0B50A4F94E84}><C:\WINDOWS\system32\BDFSU.dll>
3.删除服务
[wwwwwwww / wwwwww][Running/Auto Start]
<C:\Documents and Settings\Administrator\Application Data\wwwwww\wwwwww.exe>
4.删除驱动程序
<system32\drivers\AsIO.sys>
5.删除浏览器加载项
{265D6897-C6EC-4A41-B787-B01053B1B6B4} <C:\WINDOWS\system32\VMecwYUcqC.dll, N/A>
{2C62C71B-4E83-F93E-0A4F-A4E93E82D82D} <C:\WINDOWS\system32\EGIWY.dll, N/A>
{3D72D82C-5F94-0A4F-1B50-B5FA4F93E83E} <C:\WINDOWS\system32\XZBOR.dll, N/A>
{4E83E93D-60A5-1B50-2C61-C60B50A4F94F} <C:\WINDOWS\system32\WYANQ.dll, N/A>
{51B60A5F-72C7-2D72-3E94-D82D71C71C61} <C:\WINDOWS\system32\VJLYA.dll, N/A>
{60A5FA5F-72C7-2D72-4E83-D82D72C61B50} <C:\WINDOWS\system32\IKMZB.dll, N/A>
{71B60B60-82D8-3E83-5F94-E83E83D72C61} <C:\WINDOWS\system32\HJLYA.dll, N/A>
{82C71C61-93E9-4E94-60A5-F94F94E83D72} <C:\WINDOWS\system32\GIKXZ.dll, N/A>
{93D82D72-A4EA-5FA5-71B6-0A40A5F94E83} <C:\WINDOWS\system32\TVXKM.dll, N/A>
{A4E93E82-B5FA-60A6-82C7-1B50B60A5F94} <C:\WINDOWS\system32\MOQDF.dll, N/A>
{B5FA4F93-C60B-71B6-93D8-2C61C71B60A5} <C:\WINDOWS\system32\FHJWY.dll, N/A>
6.暴力删除/正在运行的进程
[C:\WINDOWS\system32\mxaut.dll]
[C:\WINDOWS\system32\AsIo.dll]
7.重置Winsock
8.修复API HOOK
9.上报可疑给官方:
<system32\DRIVERS\asyncmac.sys>
[C:\WINDOWS\system32\qt-dx3.dll]