SoFunction
Updated on 2025-04-13

How to clear viruses

For specific analysis of specific questions, please compare and clear when referring to the question.

Enter safe mode to operate (restart the system and hold F8 until the prompt appears, and then select Enter safe mode):

Reference for solutions:

1. Delete the following files. You can use powerRMV or Xdelbox.

C:\Program Files\NetMeeting\
C:\Program Files\common Files\Microsoft Shared\MSINFO\
C:\Program Files\Internet Explorer\PLUGINS\
C:\WINDOWS\system32\
C:\WINDOWS\system32\
C:\WINDOWS\system32\
C:\WINDOWS\system32\
C:\WINDOWS\system32\
C:\WINDOWS\system32\
C:\WINDOWS\system32\

2. Use SRENG (please go to down. Download) to delete the following items


Start the project--》Delete the following items under the registry:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      <ravmsmon><C:\Program Files\NetMeeting\>    []


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      <{798977F1-34FC-4DDD-AF6D-1B5C196B4EB4}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\>    []
      <{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\>    []
      <{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\>    [N/A]
      <{1E32FA58-3453-FA2D-BC49-F340348ACCE1}><C:\WINDOWS\system32\>    [N/A]
      <{134345F1-DACF-3452-CB7D-4620F34A1531}><C:\WINDOWS\system32\>    [N/A]
      <{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\>    [N/A]
      <{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\>    [N/A]

==================================
Start the project --> Services --> Win32 service application    Delete the following items
[smService / smService][Running/Auto Start]
    <C:\WINDOWS\system32\><N/A>
[systems / systems][Running/Auto Start]
    <C:\WINDOWS\system32\><Microsoft Corporatio>