System Repair Tool - SREng (1)

  
        SREng is divided into four parts: startup project, system repair
, intelligent scanning, and extension. Since it is not clear why the system is running slowly, the system first performs a "body check" through the "smart scan". It does a full-scale scan of the system, including startup items, browser add-ons, running processes, file associations, and more (Figure 1). When the program scan is complete, a detailed report related to the user system is given. The author learned that the situation was caused by some rogue software
.
Figure 1 Smart Scan

After determining the action of the rogue software, prepare to remove it from the system. Although rogue software is not the same as Trojans and viruses, it runs the same way. I am going to find the startup items of the rogue software first, and then clear them step by step.

In order to enhance the user's recognition ability, the new version of SREng adds startup items and service risk judgment rules, and highlights colors when suspicious content is found. Red indicates a high-risk project and blue indicates an unknown security status item. The author first checks the "registry" startup item, SREng will automatically read the contents of all startup items of the Windows system. If the default key value is found to be changed to a non-default value, a warning will pop up to remind the user to pay attention. The result is not any. Suspicious items.

I think with the gradual popularization of NT kernel operating systems such as Windows 2000, XP, and 2003, many softwares have been "advanced with the times" and started using system services. I don't think rogue software will be an exception. Let's go. Select the "Services" tab in the "Startup Project", then click the "Win32 Service Application" button, you can view the current system service in the pop-up window. By effectively managing these processes, the system can be optimized. After selecting the "Hide Microsoft Services" option, the program will automatically block the publisher's Microsoft project and find suspicious things from these non-Microsoft services. No suspicious startup items were found.

I know that in addition to using the system service
, the individual rogue software also uses the driver to start, you can see the word "driver", do not simply contact the hardware device Together, many applications use their own drivers at the bottom of the system. The advantage of this is that it not only enhances the stability of the program, but also protects itself better (Figure 2). After the SREng was completed, the "driver" project was added. After careful inspection, a driver showing red was found, named "Cnmin**.sys". After confirming that it is the driver of the rogue software, after selecting the "delete service" option, click the "Settings" button to delete the driver.

Figure 2 Driver Check

A Meng Tip: Before using the various repair software to delete system related files, be sure to back up the registry files to avoid system problems caused by accidental deletion.

Copyright © Windows knowledge All Rights Reserved