下载冰刃后[http://www.ttian.net/website/2005/0829/391.html],断开网线,什么程序都不要开,包括你的杀软,关闭系统还原,执行以下操作:
重命名sreng并运行,删除注册表启动项
<wosa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\woso.exe> []
<ztsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\ztso.exe> []
<mhsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\mhso.exe> []
<fysa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\fyso.exe> []
<jtsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\jtso.exe> []
<wlsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wlso.exe> []
<wgsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wgso.exe> []
<wmsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wmso.exe> []
<qjsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\qjso.exe> []
<rxsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\rxso.exe> []
<wdsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wdso.exe> []
<tlsa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\tlso.exe> []
<dasa><C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\daso.exe> []
<{DEC39E0E-F1F2-41E5-80B8-592A67AB0AA5}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
<{01F6EB6F-AB5C-1FDD-6E5B-FB6EE3CC6CD6}><C:\Program Files\Internet Explorer\HiJack.dll> [Microsoft Corporation]
<{09B68AD9-FF66-3E63-636B-B693E62F6236}><C:\Program Files\Internet Explorer\romdrivers.dll> [Microsoft Corporation]
<thememms><C:\WINNT\system32\thememms.dll> [N/A]
关闭sreng,重命名冰刃并运行,文件,设置,禁止进程创建,确定
卸除所有进程中的
[注意:包括冰刃自身的进程模块][C:\Program Files\Internet Explorer\HiJack.dll] [Microsoft Corporation, 1. 0. 0. 1]
C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\daso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\tlso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wdso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\rxso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wmso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wgso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\wlso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\jtso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\fyso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\ztso0.dll] [N/A, ]
[C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp\woso0.dll] [N/A, ]
模块 [在进程上右键,查看模块信息]
删除以下文件
C:\Program Files\Internet Explorer\HiJack.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk
C:\Program Files\Internet Explorer\romdrivers.dll
C:\WINNT\system32\thememms.dll
清空:
C:\DOCUME~1\ACHILL~1\LOCALS~1\Temp