【回复“不懂的新手”的帖子】
晕倒
好好的一个日志竟然弄得这么乱
真是麻烦
操作参考:
=================
打开SREng--系统修复--启动项目--注册表--用鼠标左键选中如下项目--删除
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnnt><C:\WINDOWS\mcUpdate.exe> []
<caishowmanage><C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<SOUNDM><winsmd.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<1><C:\WINDOWS\wingdi.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<Vision><> []
<DVDBurn><C:\WINDOWS\Downloaded Program Files\AfxEdit.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<doc><; c:\windows\doc.exe> []
<RavTimeXP><; C:\WINDOWS\TEMP\WUUR.exe> []
<spoolsv><; C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer> []
================
打开SREng--系统修复--浏览器加载项--用鼠标左键选中如下项目--删除所选内容
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, >
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll, Microsoft Corporation>
[BrowserHelper Class]
{2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} <C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, TODO: <公司名>>
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[Hssdtobj Class]
{5D15CEAC-3B27-4863-AAEA-93A4C8A6C57D} <C:\WINDOWS\system32\hssdtobm.dll, 易易加速科技有限公司>
[NewWebController Class]
{9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\WinSC.dll, N/A>
[DuiSo.com Search]
{E2218499-2FD4-4EED-A94A-7F0B9C6E300E} <C:\WINDOWS\system32\Inte32.dll, N/A>
[Letscool System Helper]
{F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, LETSCOOL Network Technology>
[IE标准栏]
{954F618B-0DEC-4D1A-9317-E0FC96F87865} <C:\WINDOWS\system32\amstreamxb.dll, >
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, >
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <, N/A>
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll, Microsoft Corporation>
[BrowserHelper Class]
{2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} <C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, TODO: <公司名>>
[google bar]
{479241B5-347D-41B5-A76B-202D06B52EAE} <C:\WINDOWS\Windef.dll, N/A>
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[Hssdtobj Class]
{5D15CEAC-3B27-4863-AAEA-93A4C8A6C57D} <C:\WINDOWS\system32\hssdtobm.dll, 易易加速科技有限公司>
[IE标准栏]
{954F618B-0DEC-4D1A-9317-E0FC96F87865} <C:\WINDOWS\system32\amstreamxb.dll, >
[NewWebController Class]
{9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\WinSC.dll, N/A>
[DuiSo.com Search]
{E2218499-2FD4-4EED-A94A-7F0B9C6E300E} <C:\WINDOWS\system32\Inte32.dll, N/A>
[Letscool System Helper]
{F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, LETSCOOL Network Technology>
===========================
开始--控制面板--性能和维护--管理工具--服务
禁用如下服务:
[Database information combine / DbooInfo]
[SDAgent Service / SDAgentService]
=================
开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
DbooInfo文件夹
SDAgentService文件夹
=========================
http://www.xfocus.net/tools/200605/1161.html
下载后打开IceSword
在工具栏中点击--文件--设置
勾选“禁止进线程创建”
然后结束如下进程:
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\mnsie.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\drivers\mcq\adout.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
用IceSword删除
C:\DOCUME~1\wn\LOCALS~1\Temp\8m.dll
C:\WINDOWS\Downloaded Program Files\swflash.dll
C:\WINDOWS\system32\drivers\mcq\adout.exe
C:\WINDOWS\system32\drivers\mcq\
删除完毕
把IceSword的“禁止进线程创建”前的勾去掉
====================
卸载
C:\Program Files\CaiShow Tech\
==============
删除
C:\Program Files\CaiShow Tech\
C:\WINDOWS\mcUpdate.exe
winsmd.exe(在C盘搜索)
C:\WINDOWS\wingdi.exe
C:\WINDOWS\Downloaded Program Files\AfxEdit.dll
c:\windows\doc.exe
C:\WINDOWS\TEMP\WUUR.exe
C:\WINDOWS\system32\spoolsv\
C:\WINDOWS\fonts\msshapi.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll
C:\WINDOWS\Windef.dll
C:\WINDOWS\system32\MicrosoftNet.dll
C:\WINDOWS\system32\hssdtobm.dll
C:\WINDOWS\system32\amstreamxb.dll
C:\WINDOWS\system32\WinSC.dll
C:\WINDOWS\system32\Inte32.dll
C:\WINDOWS\system32\CoolBho.dll
提示:
若正常模式下无法解决
建议进入安全模式下操作