SoFunction
Updated on 2025-04-08

, How to clear the * group

There should be a special generator, and I've encountered many

Don't write an analysis. .

Solution:

1. Download and IceSword120_cn.zip (hereinafter referred to as Ice Blade)


After downloading, place it directly on the desktop.

2. Disconnect the network and close unwanted connections.

3. Turn on the Ice Blade, set-disable thread creation, and confirm.

4. Delete the following files (just skip if prompted):


Code:
C:\Program Files\Common Files\   31791 Bytes
C:\Program Files\Internet Explorer\    27183 Bytes

C:\Program Files\Internet Explorer\   31791 Bytes

C:\Program Files\Internet Explorer\   31791 Bytes

 


These 4 are the main body, and the file names may be different. . Pay attention to the file size.

And these *s:

 
Code:
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\
C:\Windows\system32\ 



And find out if there are any suspicious files under the C-F disk. If there is any, it will be deleted.

5. Set the ice blade, restart and monitor.

6. After restarting, open SREng and delete:


Code:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

<{CC3596CB-D6C1-ECA1-AE51-DEEA63F6C21C}><C:\Program Files\Internet Explorer\>   [Microsoft Corporation]
     <{3422FB0F-95EB-458A-8B56-39552017A4EF}><C:\winnt\system32\>   []
     <{5731EA1D-6AAF-4DE9-BDDA-7B390A75B286}><C:\winnt\system32\>   []
     <{E952B8F8-D91A-4EDD-851C-EE1A0F944469}><C:\winnt\system32\>   []
     <{E03C23BD-35B7-49C2-BBCA-6D8CEC2507E3}><C:\winnt\system32\>   []
     <{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\winnt\system32\>   []
     <{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\winnt\system32\>   []
     <{0DAEBA6A-86CA-4B96-AF96-0C8C2C358FBD}><C:\winnt\system32\>   []
     <{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\winnt\system32\>   []
     <{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\winnt\system32\>   []
     <{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\winnt\system32\>   []
     <{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\winnt\system32\>   []
     <{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\winnt\system32\>   []
     <{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\winnt\system32\>   []
     <{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}><C:\winnt\system32\>   []


7. If KSR cannot be opened and the initialization error is prompted, go to KSR's directory folder.

Open the "Drag the one you want to delete to me.bat", and you will see the Ws2_32.dll or folder to it.

8. Continue to restart. . After restarting, modify the passwords such as QQ, online games, etc. .