针对fairy_ape等
清理病毒的脚本,真好用
v2.0 改进算法和命令,使程序体积更小,速度更快。
(11月21日修正程序中4处Dword值错误,解决使用本程序后无法隐藏文件的问题。已经出现该问题的电脑只需下载新的程序运行一次即可恢复正常。)
@title CLV for WinXP. . . by bicsa 2007 v2.0
@color c0
@cls
@echo.┍━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┑
@echo.│ 【 Clear Virus 批处理程序 】 │
@echo.│ │
@echo.│ 作者: Bicsa │
@echo.│ │
@echo.│ 本程序仅适用于 Windows XP 操作系统 │
@echo.│ │
@echo.┝━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┥
@echo.│ 强烈建议在【安全模式】下运行本程序 │
@echo.│ (开机按 F8 选择【安全模式】) │
@echo.├───── ─────┤
@echo.│ ┏━━━━━━━━━━━━━━━━━━┓ │
@echo.│ ┃ 程序运行需要较长时间, 请耐心等待! ┃ │
@echo.│ ┃ 程序结束时会有醒目提示 ┃ │
@echo.│ ┗━━━━━━━━━━━━━━━━━━┛ │
@echo.│ │
@echo.├───── 按 Ctrl + C 中断程序运行 ─────┤
@echo.│ │
@echo.│ │
@echo.│ │
@echo.├─────────────────────────────────────┤
@echo.┕━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┙
@echo.即将开始病毒清理
@pause
@color 79
@echo.
@echo.=============================================================================
@echo.
@echo.结束可疑进程. . .
@echo.
@ping -n 1 127.0.0.1>nul
taskkill /f /im fairy_ape.exe /im intranet.exe
taskkill /f /im Iexplorers.exe /im go.exe /im internet.exe /im lcass.exe
taskkill /f /im rundll32.exe /im rundll.exe /im rundl132.exe
taskkill /f /im win32.exe /im win33.exe /im doc.exe /im doc1.exe
taskkill /f /im rose.exe /im logo1_.exe /im logo_1.exe /im sxs.exe /im setup.exe /im wow.exe /im zt.exe
taskkill /f /im IPARMOR.exe /im Ravmond.exe /im KAVPFW.exe /im Mailmon.exe /im Ravmon.exe
taskkill /f /im 0sy.exe /im 1sy.exe /im 2sy.exe /im 3sy.exe /im 4sy.exe /im 5sy.exe /im 6sy.exe /im 7sy.exe /im 8sy.exe /im 9sy.exe
taskkill /f /im 0.exe /im 1.exe /im 2.exe /im 3.exe /im 4.exe /im 5.exe /im 6.exe /im 7.exe /im 8.exe /im 9.exe
@echo.
@echo.=============================================================================
@echo.
@echo.删除可疑服务. . .
@echo.
@ping -n 1 127.0.0.1>nul
net stop "PnP plug 0n Service"
SC DELETE "PnP plug 0n Service"
net stop intranet
SC DELETE intranet
net stop WINIO
SC DELETE WINIO
@echo.
@echo.=============================================================================
@echo.
@echo.修复关键注册表项. . .
@echo.
@ping -n 1 127.0.0.1>nul
::Close SystemRestore
REG Add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v "DisableSR" /t REG_DWORD /d 1 /f
::forbid NET Share
REG Add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /v AutoShareServer /t REG_DWORD /d 0 /f
REG Add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /v AutoSharewks /t REG_DWORD /d 0 /f
::fix EXE filetype
REG Add HKCR\.exe /f
REG Add HKCR\.exe /ve /d "exefile" /f
REG Add HKCR\.exe /v "Content Type" /d "application/x-msdownload" /f
REG Add HKCR\.exe\PersistentHandler /f
REG Add HKCR\.exe\PersistentHandler /ve /d "{098f2470-bae0-11cd-b579-08002b30bfeb}" /f
::fix TXT filetype
REG Add HKCR\.txt /f
REG Add HKCR\.txt /ve /d "txtfile" /f
REG Add HKCR\.txt /v "PerceivedType" /d "text" /f
REG Add HKCR\.txt /v "Content Type" /d "text/plain" /f
REG Add HKCR\.txt\PersistentHandler /f
REG Add HKCR\.txt\PersistentHandler /ve /d "{5e941d80-bf96-11cd-b579-08002b30bfeb}" /f
REG Add HKCR\.txt\ShellNew /f
REG Add HKCR\.txt\ShellNew /v "NullFile" /f
::view Hidden
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "RegPath" /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "Text" /d "@shell32.dll,-30501" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "Type" /d "radio" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "CheckedValue" /t REG_DWORD /d 2 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "ValueName" /d "Hidden" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "DefaultValue" /t REG_DWORD /d 2 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v "HKeyRoot" /t REG_DWORD /d 2147483649 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "RegPath" /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "Text" /d "@shell32.dll,-30500" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "Type" /d "radio" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "CheckedValue" /t REG_DWORD /d 1 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "ValueName" /d "Hidden" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "DefaultValue" /t REG_DWORD /d 2 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v "HKeyRoot" /t REG_DWORD /d 2147483649 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "Type" /d "checkbox" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "Text" /d "@shell32.dll,-30508" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "WarningIfNotDefault" /d "@shell32.dll,-28964" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "HKeyRoot" /t REG_DWORD /d 2147483649 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "RegPath" /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "ValueName" /d "ShowSuperHidden" /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "CheckedValue" /t REG_DWORD /d 0 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "UncheckedValue" /t REG_DWORD /d 1 /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden /v "DefaultValue" /t REG_DWORD /d 0 /f
REG Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy /f
REG Add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden /f
::Forder shell
REG Add HKCR\Directory\shell /f
REG Add HKCR\Directory\shell /ve /d "none" /f
REG Add HKCR\Directory\shell\find /f
REG Add HKCR\Directory\shell\find /v "SuppressionPolicy" /t REG_DWORD /d 0x80 /f
REG Add HKCR\Directory\shell\find\command /f
REG Add HKCR\Directory\shell\find\command /ve /t REG_BINARY /d 2500530079007300740065006d0052006f006f00740025005c004500780070006c006f007200650072002e006500780065000000 /f
REG Add HKCR\Directory\shell\find\ddeexec /f
REG Add HKCR\Directory\shell\find\ddeexec /ve /d "[FindFolder(\"%l\", %I)" /f
REG Add HKCR\Directory\shell\find\ddeexec /v "NoActivateHandler" /d "" /f
REG Add HKCR\Directory\shell\find\ddeexec\application /f
REG Add HKCR\Directory\shell\find\ddeexec\application /ve /d "Folders" /f
REG Add HKCR\Directory\shell\find\ddeexec\topic /f
REG Add HKCR\Directory\shell\find\ddeexec\topic /ve /d "AppProperties" /f
::Driver shell
REG Add HKCR\Drive\shell /ve /d "none" /f
REG Add HKCR\Drive\shell\find /f
REG Add HKCR\Drive\shell\find /v "SuppressionPolicy" /t REG_DWORD /d 0x80 /f
REG Add HKCR\Drive\shell\find\command /f
REG Add HKCR\Drive\shell\find\command /ve /t REG_BINARY /d 2500530079007300740065006d0052006f006f00740025005c004500780070006c006f007200650072002e006500780065000000 /f
REG Add HKCR\Drive\shell\find\ddeexec /f
REG Add HKCR\Drive\shell\find\ddeexec /ve /d "[FindFolder(\"%l\", %I)" /f
REG Add HKCR\Drive\shell\find\ddeexec /v "NoActivateHandler" /d "" /f
REG Add HKCR\Drive\shell\find\ddeexec\application /f
REG Add HKCR\Drive\shell\find\ddeexec\application /ve /d "Folders" /f
REG Add HKCR\Drive\shell\find\ddeexec\topic /f
REG Add HKCR\Drive\shell\find\ddeexec\topic /ve /d "AppProperties" /f
::SafeBoot
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot /v "AlternateShell" /d "cmd.exe" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender" /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter" /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys /ve /d "FSFilter System Recovery" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000} /ve /d "Universal Serial Bus controllers" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318} /ve /d "CD-ROM Drive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} /ve /d "DiskDrive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318} /ve /d "Standard floppy disk controller" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318} /ve /d "Hdc" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318} /ve /d "Keyboard" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318} /ve /d "Mouse" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318} /ve /d "PCMCIA Adapters" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318} /ve /d "SCSIAdapter" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318} /ve /d "System" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318} /ve /d "Floppy disk drive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F} /ve /d "Volume" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} /ve /d "Human Interface Devices" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender" /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys /ve /d "FSFilter System Recovery" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService /ve /d "Service" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers" /ve /d "Driver Group" /f
REG Add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender" /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI /ve /d "Driver Group" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys /ve /d "Driver" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC /ve /d "Service" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000} /ve /d "Universal Serial Bus controllers" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318} /ve /d "CD-ROM Drive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} /ve /d "DiskDrive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318} /ve /d "Standard floppy disk controller" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318} /ve /d "Hdc" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318} /ve /d "Keyboard" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318} /ve /d "Mouse" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318} /ve /d "Net" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318} /ve /d "NetClient" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318} /ve /d "NetService" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318} /ve /d "NetTrans" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318} /ve /d "PCMCIA Adapters" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318} /ve /d "SCSIAdapter" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318} /ve /d "System" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318} /ve /d "Floppy disk drive" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F} /ve /d "Volume" /f
REG Add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} /ve /d "Human Interface Devices" /f
::Other virs
REG Delete HKLM\SYSTEM\CurrentControlSet\Services\wgareg /f
REG Delete HKLM\SYSTEM\CurrentControlSet\Services\wgavm /f
REG Add HKLM\SOFTWARE\Microsoft\Ole /v "EnableDCOM" /d "Y" /f
REG Add HKLM\SOFTWARE\Microsoft\Ole /v "EnableRemoteConnect" /d "Y" /f
REG Delete HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters /v AutoShareServer /f
REG Delete HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters /v AutoSharewks /f
::del fariy_ape
REG Delete HKEY_CLASSES_ROOT\.fap /f
REG Delete HKEY_CLASSES_ROOT\.LAS /f
REG Delete HKEY_CLASSES_ROOT\Applications\fairy_ape.exe /f
REG Delete HKEY_CLASSES_ROOT\fap.Document /f
REG Delete HKEY_CLASSES_ROOT\LAS.Document /f
REG Delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fap /f
REG Delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.LAS /f
REG Delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\fairy_ape.exe /f
REG Delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fap.Document /f
REG Delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LAS.Document /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTRANET /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WINIO /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Intranet /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_INTRANET /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Intranet /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\WINIO /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTRANET /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Intranet /f
REG Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WINIO /f
::goto C:
@cd /d c:\
@echo.
@echo.=============================================================================
@echo.
@echo.卸载可疑控件. . .
@echo.
@ping -n 1 127.0.0.1>nul
regsvr32 /u /s lcass.dll
regsvr32 /u /s ntsvc.ocx
regsvr32 /u /s mswinsck.ocx
regsvr32 /u /s rundl132.dll
regsvr32 /u /s sws32.dll
regsvr32 /u /s vdll.dll
regsvr32 /u /s tdll.dll
regsvr32 /u /s dll.dll
regsvr32 /u /s MickNew.dll
regsvr32 /u /s MH_DLL.dll
regsvr32 /u /s TODAYZTKING.DLL
@echo.
@echo.=============================================================================
@echo.
@echo.开始删除病毒, 请耐心等待. . .
@echo.
@ping -n 2 127.0.0.1>nul
if exist %windir%\system32\fairy_ape.exe del /f/q/a %windir%\system32\fairy_ape.exe
if exist %windir%\system32\intranet.exe del /f/q/a %windir%\system32\intranet.exe
if exist %windir%\system\*.exe del /f/q/a %windir%\system\*.exe
if exist %windir%\system\*.bat del /f/q/a %windir%\system\*.bat
if exist %windir%\system\*.cmd del /f/q/a %windir%\system\*.cmd
if exist %windir%\system\*.vbs del /f/q/a %windir%\system\*.vbs
if exist %windir%\system\*.scr del /f/q/a %windir%\system\*.scr
if exist %windir%\system\*.msi del /f/q/a %windir%\system\*.msi
if exist %windir%\system\*.com del /f/q/a %windir%\system\*.com
if exist %windir%\system32\lcass.exe del /f/q/a %windir%\system32\lcass.exe
if exist %windir%\system32\lcass.dll del /f/q/a %windir%\system32\lcass.dll
if exist %windir%\system32\ntsvc.ocx del /f/q/a %windir%\system32\ntsvc.ocx
if exist %windir%\system32\mswinsck.ocx del /f/q/a %windir%\system32\mswinsck.ocx
if exist %Windir%\MickNew\MickNew.dll del /f/q/a %Windir%\MickNew\MickNew.dll
if exist %Windir%\MH_FILE\MH_DLL.dll del /f/q/a %Windir%\MH_FILE\MH_DLL.dll
if exist %Windir%\TODAYZTKING\TODAYZTKING.DLL del /f/q/a %Windir%\TODAYZTKING\TODAYZTKING.DLL
if exist %windir%\1.com del /f/q/a %windir%\1.com
if exist %windir%\doc.exe del /f/q/a %windir%\doc.exe
if exist %windir%\doc1.exe del /f/q/a %windir%\doc1.exe
if exist %windir%\intranet RD /s/q %windir%\intranet
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a %windir%\temp\*.*
del /f/s/q/a "%userprofile%\Local Settings\Temporary Internet Files\*.*"
del /f/s/q/a "%userprofile%\Local Settings\Temp\*.*"
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe bootconf.exe svchast.exe svch0st.exe svshost.exe suchost.exe
del /f/s/q/a logo1_.exe logo_1.exe sws32.dll kill.exe vdll.dll tdll.dll dll.dll
del /f/s/q/a desktop_.ini _desktop.ini internet.exe sxs.exe rose.exe rundl132.dll
del /f/s/q/a 0sy.exe 1sy.exe 2sy.exe 3sy.exe 4sy.exe 5sy.exe 6sy.exe 7sy.exe 8sy.exe 9sy.exe
del /f/s/q/a go.exe 1.exe 2.exe 3.exe 4.exe 5.exe 6.exe 7.exe 8.exe 9.exe 0.exe
::z:\
@if not exist Z:\ goto toy1
@cd /d Z:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toy1
@if not exist Y:\ goto tox1
@cd /d Y:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tox1
@if not exist X:\ goto tow1
@cd /d X:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tow1
@if not exist W:\ goto tov1
@cd /d W:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tov1
@if not exist V:\ goto tou1
@cd /d V:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tou1
@if not exist U:\ goto tot1
@cd /d U:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tot1
@if not exist T:\ goto tos1
@cd /d T:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tos1
if not exist S:\ goto tor1
@cd /d S:\
@if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tor1
if not exist R:\ goto toq1
@cd /d R:\
@if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toq1
@if not exist Q:\ goto top1
@cd /d Q:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:top1
@if not exist P:\ goto too1
@cd /d P:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:too1
@if not exist O:\ goto ton1
@cd /d O:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:ton1
@if not exist N:\ goto tom1
@cd /d N:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tom1
@if not exist M:\ goto tol1
@cd /d M:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tol1
@if not exist L:\ goto tok1
@cd /d L:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tok1
@if not exist K:\ goto toj1
@cd /d K:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toj1
@if not exist J:\ goto toi1
@cd /d J:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toi1
@if not exist I:\ goto toh1
@cd /d I:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toh1
@if not exist H:\ goto tog1
@cd /d H:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tog1
@if not exist G:\ goto tof1
@cd /d G:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tof1
@if not exist F:\ goto toe1
@cd /d F:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toe1
@if not exist E:\ goto tod1
@cd /d E:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tod1
@if not exist D:\ goto tob1
@cd /d D:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:tob1
@if not exist B:\ goto toa1
@cd /d B:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:toa1
@if not exist A:\ goto to0
@cd /d A:\
if exist RECYCLER\lcass.exe RD /s/q RECYCLER
del /f/q/a Iexplorers.exe autorun.* ghost*.exe setup.exe ww.txt
del /f/s/q/a win32.exe win33.exe go.exe sxs.exe rose.exe desktop_.ini _desktop.ini
:to0
@color c0
@echo.
@echo.
@echo.
@echo.
@echo.
@echo.
@echo.
@echo.
@echo. ┍━━━━━━━━━━━━━━━┑
@echo. │ │
@echo. │ 清理完毕! │
@echo. │ │
@echo. │ Made by Bicsa │
@echo. │ │
@echo. │ = 2007 = │
@echo. │ │
@echo. ┕━━━━━━━━━━━━━━━┙
@echo.
@echo.
@echo.
@echo.
@echo.
@echo.
@echo.
@pause
@color
@exit