========Content========
下载Icesword,菜单文件中,设置禁止进程创建,点进程,右面窗口中右击中止下列进程:
[PID: 1656][C:\WINDOWS\Explorer.EXE]
[PID: 680][c:\program files\rising\rfw\RfwMain.exe]
[PID: 880][C:\Program Files\Rising\AntiSpyware\runiep.exe]
[PID: 608][C:\WINDOWS\mhs2.exe] [N/A, N/A]
[PID: 460][C:\WINDOWS\Systemt.exe] [N/A, N/A]
[PID: 1060][C:\WINDOWS\rxs3.exe] [N/A, N/A]
[PID: 1084][C:\WINDOWS\wls3.exe] [N/A, N/A]
[PID: 272][C:\WINDOWS\msagent\AgentSvr.exe]
[PID: 2308][C:\Program Files\Rising\Rav\RsLogVw.exe]
[PID: 2940][C:\Program Files\Internet Explorer\iexplore.exe]
[PID: 2080][E:\Downloads\ruixing\sreng2\SREng.EXE]
下面文件中,依路径删除:
C:\WINDOWS\mhs2.exe
C:\WINDOWS\Systemt.exe
C:\WINDOWS\rxs3.exe
C:\WINDOWS\wls3.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp--清空这个文件夹
C:\Program Files\Common Files\Microsoft Shared\MSINFO\WinInfo.rxk
下面注册表中,删除下列值:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<mhs2><C:\WINDOWS\mhs2.exe> [N/A]
<NiceMt><C:\WINDOWS\Systemt.exe> [N/A]
<rxs3><C:\WINDOWS\rxs3.exe> [N/A]
<wls3><C:\WINDOWS\wls3.exe> [N/A]
<mytsf><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrss.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{06A48AD9-FF57-4E73-937B-B493E72F4226}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\WinInfo.rxk> [N/A]
取消禁止进程创建,重启并监视
任务管理器中重启