1. Disable System Restore before anti-virus (the Win2000 system can be ignored): Right-click my computer, properties, system restore, and close the System Restore check on all drives.
Clear temporary IE files: Open the IE point tool --> Internet option: Internet temporary files. Click "delete file" to check all offline content and click "OK" to delete the temporary files.
Close QQ and other applications. Do not double-click the disk before proceeding to the following operations.
All tools are on the desktop. Remember.
2. Use force Delete tool PowerRMV: http://post.baidu.com/f? Kz= 158203765
Fill in the following files (including the complete path), select "Stop and stop killing objects again", and click "kill". [ignore any prompts that cannot be found]
C: \ Autorun. inf
C: \ SuperDown. EXE
D: \ Autorun. inf
D: \ SuperDown. EXE
E: \ Autorun. inf
E: \ SuperDown. EXE
C: \ WINDOWS \ System32 \ ShellDown.exe
C: \ release E ~ 1 \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ QQshow.exe
C: \ Program Files \ Common Files \ System \ Updaterun.exe
C: \ Program Files \ Internet Explorer \ Connection Wizard \ isignup. sys
C: \ Program Files \ Common Files \ Microsoft Shared \ MSInfo \ IEINFO5.sys
C: \ WINDOWS \ system32 \ svchusts.exe
C: \ WINDOWS \ SYSTEM32 \ WBEM \ FYGWA. DLL
C: \ WINDOWS \ System32 \ rjkxi. dll
Restart the computer and then enter safe mode to perform the following operations:
--------------------------------------------------------------
The following operations must be performed in security mode.
[Security mode? Press F8 to enter safe mode when restarting the computer]
--------------------------------------------------------------
3. Use the SREng tool to delete the following items:
To download and use it, see the following link!
Http://hi.baidu.com/teyqiu/blog/item/f706213fc52346ec54e72351.html
[The following operations are risky. You must understand the above methods before performing the operations .]
Start the project --> the following items of the Registry
<ShellDown.exe> <C: \ WINDOWS \ System32 \ ShellDown.exe> [N/A]
<RavUptepys> <; C: \ DOCUME ~ 1 \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ QQshow.exe> [N/A]
<System> <C: \ Program Files \ Common Files \ System \ Updaterun.exe> [N/A]
<{B8A170A8-7AD3-4678-B2FE-F2D7381CC1B5}> <C: \ Program Files \ Internet Explorer \ Connection Wizard \ isignup. sys> [N/A]
<{5d06580a-08eb-4dd0-8316-ddbb5198b30c}> <C: \ Program Files \ Common Files \ Microsoft Shared \ MSInfo \ IEINFO5.sys> [N/A]
========================================
Start the project --> service --> the following project under the Win32 service application
[Svchost.exe/svchost.exe] [Stopped/Auto Start]
<C: \ WINDOWS \ system32 \ svchusts.exe> <N/A>
[Internet Protect Service/SHipING] [Running/Auto Start]
<C: \ WINDOWS \ SYSTEM32 \ RUNDLLFROMWIN2000.EXE C: \ WINDOWS \ SYSTEM32 \ WBEM \ FYGWA. DLL, Export 1087> <Microsoft Corporation>
[Network Engine/Patterns] [Stopped/Auto Start]
<C: \ WINDOWS \ System32 \ svchost.exe-k netsvcs --> C: \ WINDOWS \ System32 \ rjkxi. dll> <Microsoft Corporation>
Finally, WINDOWS cleanup assistant cleanup reference
Http://post.baidu.com/f? Kz= 149133630