下载附件(冰刃),解压,然后拔掉网线,运行ICESWORD.exe,完成以下操作:
1、文件--设置--勾选“禁止进线程创建”--确定
2、点“注册表”标签,删除以下项:
(1)注册表值项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{71A78CD4-E470-4a18-8457-E0E0283DD507}>
<{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}>
<{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}>
<{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}>
<{D3112B69-A745-4805-874E-ABD480EA1299}>
<{EB9660D8-E1CD-4ff0-B4A9-00CD907F928A}>
<{F0930A2F-D971-4828-8209-B7DFD266ED44}>
<{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC}>
<{00240024-0024-0024-0024-00240024BB15}>
<{DA56B183-A731-402b-9235-2CB8803E212D}>
<{EA4D8F95-8F2E-4658-A234-E8F4C9AC21C5}>
<{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}>
<{BA4B5EBD-AB43-4c2b-84F5-F1AD85E79E4A}>
<{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}>
<{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<mjyscrvg.dll>
<zurxqnbk.dll>
<jgtbhfog.dll>
<myznueqh.dll>
<qqehpcsh.dll>
<slbiopfs2.dll>
<thktcbui.dll>
<ajrsiapt.dll>
<scrruncqsj.dll>
<dbxevzrm.dll>
<qbqhbunl.dll>
<ogoxioqb.dll>
<wtsapi32yt2.dll>
<okoqaito.dll>
<ejmfcbrg.dll>
<vkhdcwtw.dll>
<ivazitri.dll>
<mngtvrtj.dll>
<pflfridb.dll>
<whlewhym.dll>
<zyrqjgan.dll>
<gayppfuy.dll>
<mvgonepj.dll>
<jzpixbgo.dll>
<eutslnru.dll>
<eytmdoch.dll>
<uxjjfisz.dll>
(2)注册表子项:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\60ddd76cb98ec134]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdsys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBKernel32]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jqzgfpy]
3、点“文件”标签,按路径找到和删除以下文件(右键以下文件,选“删除”或“强制删除”,如果都无效,则在步骤5之后,运行WINRAR删除ICESWORD不能删除的文件):
C:\60ddd76cb98ec134.dat
C:\WINDOWS\system32\cdcd.sys
C:\WINDOWS\system32\DRIVERS\HBKernel32.sys
C:\WINDOWS\system32\jqzgfpy.sys
4、文件--设置--取消“禁止进线程创建”的勾选--确定
5、重启电脑
6、完成可能在步骤3处遗留的尾巴任务
7、运行SRENG扫描工具,扫描上传新日志。