Download IceSword1.18
1. Open Icesword1.18.exe
2. File--Settings--check before "Prohibit thread creation"--OK
3. Click "Folders"--find "c:/windows/webwork/webwork.nls and c:/windows/webwork/webwork. DLL "--right-click-delete (if Delete does not restart after deleting the line)
4. Http://www.kztechs.com/sreng/sreng2.zip Download system Repair Engineer 2.2.6.605
5. Run the SREng.exe inside
6. Click on "Start Project" in the main screen and webwork. DLL, click "Delete"
7. Start-run-enter "regedit"--Determine
8. Delete the following entries in the registry:
Hkey_classes_root/clsid/
Delete: {4c611512-2c1d-44b2-a044-872ad2ad5a61}
hkey_local_machine/system/currentcontrolset/services/
Delete: Albus
----------------------------------------------------------
The second method:
Use the following method to resolve:
1. The rising monitoring and firewall are closed (remember to turn all monitoring off, including all brand anti-virus software) and then into the Control Panel-Add the removal program-the WebWork uninstall-follow the prompts to fill in the Verification code (all the numbers, carefully identified, Adjust the display resolution to 1024x768) to completely uninstall.
And then reboot, OK, pull.
Virus Name: TROJAN.DL.AGENT.XDW
The virus will automatically download the virus package to the website, with the rising anti-virus software friends can do the following:
1. First of all, the machine in the network mode, with the right mouse click on the desktop in the lower right corner of the monitoring icon, point Disable all monitoring, so that monitoring into a red umbrella.
2. Open Control Panel, find WebWork in "Add Remove Programs", click "Change/Remove" to uninstall. Note: After the point uninstall, there will be an uninstall interface requirements to see the additional code in the window, if the firewall is installed, will pop up a network prompt, be sure to choose to allow the pass, otherwise the additional code display does not come out. After you enter the additional code correctly, you should manually click "Confirm" and not press ENTER. To properly uninstall. Click Enter the default action is to cancel the uninstallation.
3. After the uninstall, the overall antivirus, should also kill one.
I use TT Internet, recently browsing the Web page often pop up IE ads window, the machine also become very slow, very annoying. I use rising antivirus, also no use, so pop ie ads. And then I killed the guest with a Trojan horse, and I found c:/windows /webwork/webwork.dll and c:/windows/webwork/webwork.nls two files infected with the TROJAN.DL.AGENT.XDW virus. I put the whole c:/windows/ WebWork folder to completely delete, but a refresh, again, and then kill, or there is a virus, depressed! I checked the internet, in the Baidu snapshot found a good way to use Unlocker1.8.5 in safe mode to kill. After entering safe mode, install Unlocker and locate c:/windows/ WebWork folder, right-click Unlocker, and then delete the entire folder, refresh again, C:/windows/webwork folder no longer appear, all ok! my view of Baidu snapshot address: http://cache.baidu.com/c?word=webwork%3B%B2%A1%B6%BE&url=http%3A//bbs% 2efhren%2ecom/showthread%2ephp%3fthreadid%3d2450&b=11&a=1&user=baidu Unlocker1.8.5 Green Edition download address: Http://cnc.xdowns.com/UploadFile/2006-9/20069717525241545.rar |
&nbs P; |