垃圾軟件反刪除批處理文件
復制下列內容 存為文本文件:uninstall.bat,執行,如果跳出選擇框,請選擇全部卸載,如果跳出沒有模塊,說明電腦里沒有這個流氓

rem 刪除 kao 3721
rundll32.exe C:\PROGRA~1\3721\Assist\asbar.dll,RunSettings -uninstall
Rundll32.exe %windir%\downlo~1\CnsMin.dll,RunSettings -uninstall
Rundll32.exe %windir%\downlo~1\CnsMin.dll,ControlPanel
regsvr32 /u /s %windir%\downlo~1\CnsMin.dll

regsvr32 /u /s C:\PROGRA~1\3721\Assist\asbar.dll
regsvr32 /u /s C:\PROGRA~1\3721\helper.dll
regsvr32 /u /s C:\PROGRA~1\YiSou\yisou.dll

rem 刪除 yahoo
regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL

rem 刪除CDN
rem C:\PROGRA~1\CNNIC\Cdn\cdnunins.exe
regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\iesrch.dll
regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll

regsvr32 /u /s C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL

regsvr32 /u /s %windir%\system32\cdnns.dll
regsvr32 /u /s %windir%\System32\jklpif.dll
regsvr32 /u /s %windir%\system32\stdup.dll
regsvr32 /u /s %windir%\system32\STDSVER.DLL

rem 刪除 baidu
rundll32.exe C:\PROGRA~1\baidu\bar\BaiduBar.dll,Uninstall
regsvr32 /u /s %windir%\DOWNLO~1\BDSrHook.dll
regsvr32 /u /s %windir%\DOWNLO~1\BDHelper.dll
regsvr32 /u /s %windir%\DOWNLO~1\BDPlugin.dll
regsvr32 /u /s C:\PROGRA~1\Baidu\Bar\BaiduBar.dll

rem 刪除QQ搜索
regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\IEHelp.dll
regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\IEHelp1.dll

rem 刪除 MSN 搜索條
regsvr32 /u /s C:\PROGRA~1\MSNToo~1\010126~1.0\zh-cn\msntb.dll

rem 刪除 DUDU 搜索條
regsvr32 /u /s C:\PROGRA~1\DuDu\DddClient\dddiemon.dll
regsvr32 /u /s C:\PROGRA~1\DuDu\DddClient\dddmext.dll

del %windir%\DOWNLO~1\BDSrHook.dll  /q
del %windir%\DOWNLO~1\BDHelper.dll  /q
del %windir%\DOWNLO~1\BDPlugin.dll  /q
del %windir%\system32\cdnns.dll     /q
del %windir%\System32\jklpif.dll    /q
del %windir%\system32\stdup.dll     /q
del %windir%\system32\STDSVER.DLL   /q
del %windir%\downlo~1\CnsMin.dll    /q

rem 刪除Accoona
regsvr32 /u /s C:\PROGRA~1\Accoona\AToolbarCN.dll
regsvr32 /u /s C:\PROGRA~1\Accoona\atoolbar.dll

rem 刪除xBar
regsvr32 /u /s C:\PROGRA~1\xBar\xBarHelper.dll

regsvr32 /u /s %windir%\System32\xunleibho_v8.dll

rem 刪除很棒
regsvr32 /u /s C:\PROGRA~1\HBClient\hapast.dll
rem 劃詞
C:\PROGRA~1\HuaCi\huaci\mUin.exe

regsvr32 /u /s C:\PROGRA~1\CoolWebsite\QuickLink.dll
regsvr32 /u /s %windir%\system32\shwasobj.dll
regsvr32 /u /s %windir%\system32\msibm\cfsbho.dll

rem 刪除桌面傳媒
MsiExec.exe /I{FE41A479-E056-40A5-982C-D149B5D6712D}
regsvr32 /u /s "C:\Program Files\Desktop Media\Cast\dmbar.dll"

C:\PROGRA~1\CoolWebsite\uninst.exe
rem 刪除劃詞
C:\PROGRA~1\wsearch\mUnInstall.exe

regsvr32 /u /s C:\Docume~1\AllUse~1\Applic~1\Microsoft\IEHelper\IEHelper200631_8913.dll
%windir%\system32\msibm\Uninstall.exe
C:\PROGRA~1\CNNIC\Cdn\cdnunins.exe


垃圾軟件反刪除注冊表文件
復制下列內容存為文本文件:uninstall.reg,執行

REGEDIT4

;
[-HKEY_LOCAL_MACHINE\SOFTWARE\3721]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Angling.AntiFish]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Angling.AntiFish.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Assist.EasyAssist]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoLive.Live]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoLive.Live.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{141A5E19-BDCB-4E27-A3D7-9E16503BC05B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADKiller.ADKillerObj]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADKiller.ADKillerObj.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B0E7716-898E-48CC-9690-4E338E8DE1D3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EB2B422-C9EE-46C4-A471-1E79C7517B1D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB936323-19FA-4521-BA29-ECA6A121BC78}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CnsHelper.CH]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CnsMinHK.CnsHook]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CnsMinHK.CnsHook.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CoolBar.CoolBarObj]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CoolBar.CoolBarObj.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FFlash.FlashObjectInterface]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FFlash.FlashObjectInterface.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{172862CD-9D35-40E7-BAF2-BA7ECF043B9C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1BB0ABBE-2D95-4847-B9D8-6F90DE3714C1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D10645F-A553-426E-9923-C3ABF846EA41}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{48E688C8-609F-4B08-944E-3C7FAB99CD08}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7436DB12-1A7A-4D87-A4E0-713EC9D86050}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{924F5B3A-7A27-484A-B873-E855C9708667}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C3A9F7F8-8862-496A-B8A4-25D4140B7DBC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19069804-2CF0-4357-B696-BA6E9AAD99EF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7354662F-CAA3-448B-BC01-04F55A2DCA35}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{95A9BBCA-4EC1-4A9E-91AA-1D9633C38D0E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D4839331-534D-4D0C-875F-D25AF6A10CCC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F97E75A4-0103-4F27-A752-327B600B1130}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZsMod.AxObj]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZsMod.AxObj.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000000-0000-0001-0001-596BAEDD1289}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{507F9113-CD77-4866-BA92-0E86DA3D0B97}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{59BC54A2-56B3-44a0-93E5-432D58746E26}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{5D73EE86-05F1-49ed-B850-E423120EC338}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FD00D911-7529-4084-9946-A29F1BDF4FE5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=-
"CustomizeSearch"=-
"OCustomizeSearch"=-
"OSearchAssistant"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{BB936323-19FA-4521-BA29-ECA6A121BC78}"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38928D50-8A48-44C2-945F-D2F23F771410}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB936323-19FA-4521-BA29-ECA6A121BC78}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{D157330A-9EF3-49F8-9A67-4141AC41ADD4}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"helper.dll"=-
"CnsMin"=-
"assistse"=-
"hbpassport"=-
"YLive.exe"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CnsMin]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1B0E7716-898E-48cc-9690-4E338E8DE1D3}]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CNSMINKP]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CnsMinKP]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\!搜一搜]
[-HKEY_CURRENT_USER\Software\3721]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"CNSMenu"=-
"CNSHint"=-
"CNSReset"=-
"CNSEnable"=-
"CNSList"=-
"CNSAutoUpdate"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{BB936323-19FA-4521-BA29-ECA6A121BC78}"=-

;
[-HKEY_CLASSES_ROOT\CLSID\{EED92A43-CFCE-4548-BD73-B0A405470ED5}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35980F6E-A137-4E50-953D-813BB8556899}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update"=-
"CdnCtr"=-
"renewup"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CDNCLIENT]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
"{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EED92A43-CFCE-4548-BD73-B0A405470ED5}"=-

;去除stdup.dll這個流氓
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\StdService]

;
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BIE"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}]
[-HKEY_CLASSES_ROOT\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B580CF65-E151-49C3-B73F-70B13FCA8E86}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B580CF65-E151-49C3-B73F-70B13FCA8E86}"=-

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索MP3]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索圖片]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索新聞]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索歌詞]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索網頁]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-搜索貼吧]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\百度-詞典搜索]

;刪除Tencent地址搜索欄
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\上傳到QQ網絡硬盤]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\添加到QQ自定義面板]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\添加到QQ表情]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\用QQ彩信發送該圖片]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AddrPlus3"=-

[-HKEY_CLASSES_ROOT\CLSID\{0C7C23EF-A848-485B-873C-0ED954731014}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C7C23EF-A848-485B-873C-0ED954731014}]
[-HKEY_CLASSES_ROOT\CLSID\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C7C23EF-A848-485B-873C-0ED954731014}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}"=-

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks]
"{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}"=-

;刪除不知道是什么流氓的東西
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Universal Disk Manager]
;刪除病毒 IRJIT.DLL
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BNESS]

;刪除Kugoo
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A9930D97-9CF0-42A0-A10D-4F28836579D5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\使用KuGoo3下載(&K)]

;刪除網絡這只蠢豬,很棒這個流氓,huaci
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PigUpdate"=-
"MoveSearch"=-
"hdp"=-
"hbpassport"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CdnCtr"=-
"mscfs"=-
"Iehelper"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1A199C20-DE2B-4838-AE3F-B5257ECE2B7E}]

;刪除劃詞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoveSearch"=-




____________________________________________________________________________________________


今天,使用‘惡意軟件清理助手’時,劃詞搜索刪不掉!以前也是清理不干凈,但是每次啟動也不加載,今天居然每次啟動都加,而且怎么刪也刪不掉!
意識到,這垃圾升級了,現在死皮賴臉的住在系統里!以前,你留點殘余也就算了,現在真的很過分了!劃詞搜索,這個垃圾軟件中的精品!干掉它!

刪掉系統目錄中的,\Program Files\huaci目錄!居然刪不掉!
搜搜注冊表,關鍵詞:huaci,zsearch,劃詞,movesearch等找出來都刪掉!重啟!
這垃圾依然還在!真是茅坑里的石頭!
我使用Unlocker軟件刪掉了劃詞目錄,總算每次啟動系統內存無劃詞了!

但是每次啟動項里還有,而且清理助手也是刪不干凈!現在不影響你正常使用!
清理到以上就可以了!如果想清理干凈!請看下文!轉載部分比較麻煩,一般到這就可以了!


轉載:
中搜劃詞刪除全攻略
http://www.pcpro.com.cn/bbs/viewthread.php?tid=28509

中搜劃詞搜索刪除全攻略
昨天重新安裝電腦的時候,不幸安裝了中搜的劃詞搜索和網絡豬.于是上網希望找到解決方案.發現網上早已經怨聲載道,原來這是個”流氓”軟件,”流氓”到比3721等還厲害,十分難刪除.我參考了網上提供的幾種方法,比如直接卸載,安全模式刪除,安全模式下使用殺毒軟件,以及網友極力推薦的各種反間諜工具,但是收效甚微.最后,我終于在自己的摸索下找到了一種安全的,完整的刪除方法,于是拿出來與大家分享.
1.首先到添加/刪除程序下找是否有” 劃詞搜索”,如果有的話就卸載,如果沒有的話,請看第二步.
2.重新啟動電腦,在這里我們要使用windows的恢復控制臺.
所以你要插入一張系統的安裝盤,然后改為從光驅啟動,當出現”歡迎安裝”字樣時,摁”R”鍵.,進入控制臺,輸入”1”(就是你的C盤目錄的位置),然后輸入管理員密碼.進入DOS界面,(我進的是98DOS,進XP安全模式不管用!-zeroka)
a.輸入 cd system32/drivers
b.進入drivers下,然后輸入 del abhcop.sys,
c.再輸入del hcalway.sys
d.再輸入exit,系統就會重新啟動.
(PS:如果無法刪除的話,應該是文件為只讀權限,使用attrib –R filename去除只讀屬性,再刪除)
3.重啟后進入windows,分別刪除以下目錄.
· %ProgramFiles%\wsearch
· %ProgramFiles%\HuaCi
· %UserProfile%\Start Menu\Programs\Startup\劃詞搜索.Ink
· %UserProfile%\Start Menu\Programs\劃詞搜索.lnk
(ps:你這時候也可以使用你的殺毒軟件先殺毒,如果你的norton或卡巴一開始能夠掃描到病毒,但無法刪除的話,這時候應該可以了,當然如果不行,只好在安全模式下殺毒啦)
4.在運行中輸入regedit,然后刪除以下鍵值就可以了.(以下使用‘惡意軟件清理助手’就可以了-zeroka)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run中的"MoveSearch" = "%ProgramFiles%\wsearch\Search.exe"
以及以下所有的子鍵,沒有就不用刪了:
HKEY_CLASSES_ROOT\CLSID\{594BE7B2-23B0-4FAE-A2B9-0C21CC1417CE}
HKEY_CLASSES_ROOT\Interface\{4E1ACE40-F681-4CC4-A7C0-AD1E6C9AD86F}
HKEY_CLASSES_ROOT\Interface\{A07E6B9B-BB30-4381-A9D8-FABB0648BCEF}
HKEY_CLASSES_ROOT\TypeLib\{FD536575-73F7-42A3-9E9F-11688F1A006A}
HKEY_CLASSES_ROOT\TypeLib\{C5CE084B-31E0-4B34-A33A-82B4EA913CF8}
HKEY_CLASSES_ROOT\SearchM.Com
HKEY_CLASSES_ROOT\SearchM.Com.1
HKEY_CLASSES_ROOT\SearchM.Search
HKEY_CLASSES_ROOT\SearchM.Search.1
HKEY_CURRENT_USER\Software\Pig Move Search
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CDSearch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\劃詞搜索
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abhcop
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hcalway
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abhcop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hcalway
其實我這篇文章參考了symantec的的文章,哈哈,我自己哪有那么厲害啊,下面給出原文的地址:
http://www.symantec.com/avcenter/venc/data/pf/adware.pigsearch.html