Board logo

标题: [转帖]批处理清除威金 [打印本页]

作者: chinanic    时间: 2007-1-28 09:49     标题: [转帖]批处理清除威金

没试过,有机会的兄弟试下。哈哈。。 :16:  :16:

将以下代码分别存为“*.bat”运行即可
  1. @echo off
  2. title 清除威金(logo_1,熊猫烧香)病毒最新变种工具
  3. @echo 清除VIKING病毒最新变种工具
  4. @echo -------------------------------------------------------
  5. @echo www.dnqw.com
  6. @echo VIKLIG病毒,专杀工具,请复制此代码 保存为.bat后缀的批处理文件双击运行即可.
  7. @echo --------------------------------------------------------
  8. pause
  9. if exist %windir%\rundl132.exe echo ---报告,发现有威金病毒
  10. if exist %windir%\logo_1.exe echo ---报告,发现有威金病毒
  11. //杀viking进程
  12. tskill logo_1
  13. tskill rundl132
  14. tskill zt
  15. tskill wow
  16. tskill logo1_
  17. tskill Ravmon
  18. tskill Eghost
  19. tskill Mailmon
  20. tskill KAVPFW
  21. tskill IPARMOR
  22. tskill Ravmond
  23. taskkill /f /im 0sy.exe
  24. taskkill /f /im 1sy.exe
  25. taskkill /f /im 2sy.exe
  26. taskkill /f /im 3sy.exe
  27. taskkill /f /im 4sy.exe
  28. taskkill /f /im 5sy.exe
  29. taskkill /f /im 6sy.exe
  30. taskkill /f /im 7sy.exe
  31. taskkill /f /im 8sy.exe
  32. taskkill /f /im 9sy.exe
  33. //删除木马
  34. del d:\_desktop.ini /f/s/q/a
  35. del c:\Program Files\_desktop.ini
  36. del %Windir%\MickNew\MickNew.dll
  37. del %Windir%\MH_FILE\MH_DLL.dll
  38. del %Windir%\_desktop.ini
  39. del %Windir%\TODAYZTKING\TODAYZTKING.DLL
  40. attrib -h -r -s c:\go.exe
  41. del c:\go.exe
  42. del c:\setup.exe
  43. attrib -h -s -r c:\autorun.inf
  44. del c:\autorun.inf
  45. attrib -h -r -s d:\go.exe
  46. del d:\go.exe
  47. del d:\setup.exe
  48. attrib -h -s -r d:\autorun.inf
  49. del d:\autorun.inf
  50. del e:\setup.exe
  51. attrib -h -r -s e:\go.exe
  52. del e:\go.exe
  53. attrib -h -s -r e:\autorun.inf
  54. del e:\autorun.inf
  55. attrib -h -r -s f:\autorun.inf
  56. del f:\go.exe
  57. del f:\setup.exe
  58. attrib -h -s -r f:\autorun.inf
  59. del f:\autorun.inf
  60. attrib -h -r -s g:\go.exe
  61. del g:\go.exe
  62. del g:\setup.exe
  63. attrib -h -s -r g:\autorun.inf
  64. del g:\autorun.inf
  65. del h:\go.exe
  66. del h:\setup.exe
  67. attrib -h -s -r g:\autorun.inf
  68. del h:\autorun.inf
  69. del i:\go.exe
  70. attrib -h -s -r g:\autorun.inf
  71. del i:\autorun.inf
  72. del i:\setup.exe
  73. del j:\go.exe
  74. attrib -h -s -r g:\autorun.inf
  75. del j:\autorun.inf
  76. del j:\setup.exe
  77. del %windir%\system\Logo1_.exe
  78. del %windir%\rundl132.exe
  79. del %windir%\vDll.dll
  80. del %windir%\Dll.dll
  81. del %windir%\0Sy.exe
  82. del %windir%\1Sy.exe
  83. del %windir%\2Sy.exe
  84. del %windir%\3Sy.exe
  85. del %windir%\5Sy.exe
  86. del %windir%\1.com
  87. @echo ^_^ 报告老大,VIKING已经全都被处死
  88. @echo 真累哈,再给你的系统免疫下,不需要的话请直接退出
  89. pause
  90. //免疫系统
  91. echo > %windir%\Logo1_.exe
  92. echo > %windir%\rundl132.exe
  93. echo > %windir%\0Sy.exe
  94. echo > %windir%\vDll.dll
  95. echo > %windir%\1Sy.exe
  96. echo > %windir%\2Sy.exe
  97. echo > %windir%\rundll32.exe
  98. echo > %windir%\3Sy.exe
  99. echo > %windir%\5Sy.exe
  100. echo > %windir%\1.com
  101. echo > %windir%\exerouter.exe
  102. echo > %windir%\EXP10RER.com
  103. echo > %windir%\finders.com
  104. echo > %windir%\Shell.sys
  105. echo > %windir%\kill.exe
  106. echo > %windir%\sws.dll
  107. echo > %windir%\sws32.dll
  108. echo > %windir%\uninstall\rundl132.exe
  109. echo > %windir%\SVCHOST.exe
  110. echo > %windir%\WINLOGON.exe
  111. echo > %windir%\RUNDLL32.EXE
  112. echo > C:\"Program Files"\svchost.exe
  113. echo > C:\"Program Files"\"Internet Explorer"\svchost.exe
  114. echo > %windir%\Download\svchost.exe
  115. echo > %windir%\system32\wldll.dll
  116. attrib %windir%\Logo1_.exe +s +r +h
  117. attrib %windir%\rundl132.exe +s +r +h
  118. attrib %windir%\0Sy.exe +s +r +h
  119. attrib %windir%\vDll.dll +s +r +h
  120. attrib %windir%\1Sy.exe +s +r +h
  121. attrib %windir%\2Sy.exe +s +r +h
  122. attrib %windir%\rundll32.exe +s +r +h
  123. attrib %windir%\3Sy.exe +s +r +h
  124. attrib %windir%\5Sy.exe +s +r +h
  125. attrib %windir%\1.com +s +r +h
  126. attrib %windir%\exerouter.exe +s +r +h
  127. attrib %windir%\EXP10RER.com +s +r +h
  128. attrib %windir%\finders.com +s +r +h
  129. attrib %windir%\Shell.sys +s +r +h
  130. attrib %windir%\kill.exe +s +r +h
  131. attrib %windir%\sws.dll +s +r +h
  132. attrib %windir%\sws32.dll +s +r +h
  133. attrib %windir%\uninstall\rundl132.exe +s +r +h
  134. attrib %windir%\SVCHOST.exe +s +r +h
  135. attrib %windir%\WINLOGON.exe +s +r +h
  136. attrib %windir%\RUNDLL32.EXE +s +r +h
  137. attrib C:\"Program Files"\svchost.exe +s +r +h
  138. attrib C:\"Program Files"\"Internet Explorer"\svchost.exe +s +r +h
  139. attrib %windir%\Download\svchost.exe +s +r +h
  140. attrib %windir%\system32\wldll.dll +s +r +h
  141. net share c$ /del
  142. net share d$ /del
  143. net share e$ /del
  144. net share f$ /del
  145. net share admin$ /del
  146. net share ipc$ /del
  147. cls
  148. @echo -------------------------------------
  149. @echo viking已经全部被我杀完拉,哈,厉害吧
  150. @echo 系统已经成功免疫!
  151. @echo 谢谢你的使用,请重启您的电脑!
  152. @echo -------------------------------------
  153. pause
  154. 禁止Viking病毒运行补丁.reg
  155. Windows Registry Editor Version 5.00
  156. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
  157. "DisallowRun"=dword:00000001
  158. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\DisallowRun]
  159. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun]
  160. "**delvals."=" "
  161. "1"="0Sy.exe"
  162. "2"="1.com"
  163. "3"="1Sy.exe"
  164. "4"="2Sy.exe"
  165. "5"="3Sy.exe"
  166. "6"="5Sy.exe"
  167. "7"="dll.dll"
  168. "8"="logo1_.exe"
  169. "9"="rundl132.exe"
  170. "10"="vdll.dll
复制代码

作者: 坏的刚刚好    时间: 2007-2-3 22:47     标题: [转帖]批处理清除威金

我中过;
现在有专杀了吧。




欢迎光临 黑色海岸线论坛 (http://bbs.thysea.com/) Powered by Discuz! 7.2