SREng的基本操作:
http://forum.ikaka.com/topic.asp?board=36&artid=8341507
确认下这个<SoundMan><SOUNDMAN.EXE> [N/A]
删除启动项:
<iesearch><iesearch.exe> []
<schedl><C:\WINDOWS\Help\schedl.exe> []
<visin><C:\WINDOWS\system32\visin.exe> [N/A]
<{559AFD5B-159F-ACD8-954C-ACD545FA6585}><C:\WINDOWS\system32\jzepri.dll> [N/A]
<{2562452F-FA36-BA4F-892A-FF5FBBAC5312}><C:\WINDOWS\system32\mybpri.dll> [N/A]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll> [N/A]
编辑AppInit_DLLs ,将其值清空
停止并禁用驱动:
dforibx / dforibx
重启系统,显示隐藏文件,删除:
C:\WINDOWS\system32\iesearch.exe或C:\WINDOWS\iesearch.exe
C:\WINDOWS\Help\schedl.exe
C:\WINDOWS\system32\visin.exe
C:\WINDOWS\system32\jzepri.dll
C:\WINDOWS\system32\mybpri.dll
C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll
C:\WINDOWS\system32\xyepri.dll
system32\drivers\dforibx.sys
如不能解决,将进程部分补上.