封堵445端口; 或打永恒之蓝漏洞补丁
在AF等设备添加规则,限制访问下列域名和IP:
ftp.ftp0930.host
pool.minexmr.com
raw.githubusercontent.com
wmi.1217bye.host
own.mysking.info
js.ftp0930.host
js.mykings.top
ftp.ftp0118.info
ok.mymyxmra.ru
mbr.kill0604.ru
173.208.139.170
35.182.171.137
45.58.135.106
103.213.246.23
78.142.29.152
74.222.14.61
18.218.14.96
223.25.247.240
223.25.247.152
103.95.28.54
23.88.160.137
81.177.135.35
78.142.29.110
174.128.239.250
66.117.6.174
使用Autoruns,删除启动项:start
使用Autoruns,删除计划任务: Mysa、Mysa1、Mysa2、Mysa3、ok
使用Autoruns,删除WMI:fuckyoumm4
删除病毒母体:C:\Windows\system\my1.bat
https://www.freebuf.com/vuls/194515.html
原文:https://www.cnblogs.com/yyxianren/p/12378248.html