升级内容[VirusCleaner V1.3.4 [20140616] ]:
链接: https://pan.baidu.com/s/1NE34XYcDbOTtPRQGHuzZrw?pwd=5jwq
1.修复全盘搜索的BUG。
2.提升恢复显示被隐藏文件夹的速度。
3.修正了文件目录。
有两个问题需要强调: - 因为涉及到修改注册表等敏感操作,可能会被360等杀毒软件拦截,请允许放行。
- 设置好的有些内容可能只是普通文件,但为病毒所利用,请根据自己情况判断。
- 改善SVCHOST.exe内存使用量高的判断,对彻底杀毒十分必要,但也可能导致系统异常,甚至蓝屏死机!重启即可。
为什么需要批处理病毒清理助手VirusCleaner? - 有些U盘病毒并不能为360等杀毒软件发现和查杀,比如同名文件夹病毒,但它却困扰着许多人。而本程序对同名文件夹病毒和随机名称病毒具有很好的发现和查杀功能。——这个可不是吹牛!
- 本程序原本是本人杀毒专用辅助工具,因结合同名文件夹病毒专杀等功能,经过多方测试成功有效,一来演示杀毒模板的作用,二来方便传播杀毒方法。
- 本程序核心功能:一是定制杀毒,二是提高系统运行速度。为许多菜鸟带来福音。
最新版请看以下代码:
- @echo off&title VirusCleaner V1.3.4 [20140616] by cjiabing &setlocal EnableDelayedExpansion&COLOR 0c
- :StartVirusCleaner
- cls
- echo;&echo;
- echo 批处理病毒清理助手
- echo;
- echo;
- echo 1. 可查杀常见U盘病毒、同名文件夹病毒、随机名称病毒。
- echo 恢复被隐藏文件夹,修复映像劫持。
- echo 一键结束非系统进程、清理系统垃圾、自启动项、任务计划。
- echo;
- echo 2. 请插入U盘杀毒,可避免交叉、反复中毒。
- echo 请保存好数据,关闭其他程序后再开始杀毒!
- echo 如遭到其他杀毒软件拦截,请允许运行!
- echo;
- echo 3. 声明:适用于普通WindowsXP、Windows7系统。
- echo 使用和修改本程序须自担风险,由此产生一切后果与作者无关!
- echo;
- echo; ———————————————————————————————————————
- if not exist %SYSTEMDRIVE%\病毒隔离区 md %SYSTEMDRIVE%\病毒隔离区>nul
- if not exist "%SYSTEMDRIVE%\病毒隔离区\%~fn0" copy "%~f0" %SYSTEMDRIVE%\病毒隔离区\ >nul
- if exist %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini (
- for /f "tokens=*" %%a in (%SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini) do %%a>nul 2>nul
- REM if /i "%1"=="AR" (set Autorun=1) else set AutoMode=1
- goto [StartVirusKill]
- ) else call :CreateInifile "%~f0"
- :[ParameterSetting]
- REM [可根据需要修改和设置的内容项目]
- set Clean=1
- REM 一键清理临时文件1,否则0
- set Manual=1
- REM 手动清理病毒1,否则0
- set Autorun=0
- REM 随机自启动1,否则0
- set AutoMode=0
- REM 自动杀毒模式1,否则0
- set Search=2
- REM 搜索所有盘符所有文件1,搜索所有盘符2,不搜索0
- set FixIFEO=0
- REM 修复映像劫持1,否则0
- set VirusProcessName=IEXPLORE.EXE SuCH0ST.EXE down.EXE boot.EXE systen.EXE expl0rer.EXE fun.EXE Rar.exe
- REM 结束进程【将病毒进程名称加入以上设置,并以空格隔开】
- set VirusFileNameSys32=mailbody.txt ok.txt out.txt output.txt mail3.vbe Attusb.dll ativcox.dll autousb.bat WIN.bat dd.bat SuCH0ST.exe down.exe boot.exe 1.RMVB fun.exe expl0rer.exe
- REM 删除文件【将系统目录 %SYSTEMROOT%\system32 中的病毒文件名加入以上设置,并以空格隔开;请谨慎添加,避免误删!】
- set VirusFileNameSys=XP-*.EXE winvcreg.exe og.dll ul.dll og.EDT 21c0.EDT 21c0.inf 69fe.inf com.run dp1.fne eAPI.fne HtmlView.fne internet.fne krnln.fnr RegEx.fnr shell.fne spec.fne msdll.dll Wsctf.exe expl0rer.exe
- REM 搜索C盘并删除文件【将根目录 %SYSTEMDRIVE% 中的病毒文件名加入以上设置,并以空格隔开;请谨慎添加,避免误删!】
- set VirusSearchfFileName=autorun.inf lpk.dll SuCH0ST.EXE down.EXE boot.EXE systen.EXE expl0rer.EXE fun.EXE
- REM 搜索全盘并删除文件【将病毒文件名加入以上设置,并以空格隔开;请谨慎添加,避免误删!】
- set VirusServiceName=DNSSystem AppMgmt
- REM 停用服务项【将被病毒利用的服务名(缩写)加入以上设置,并以空格隔开】
- :[StartVirusKill]
- REM -----------------------------------------------------------------------------
- set "UDrive=for /f "skip=1" %%i in ('wmic logicaldisk where "drivetype='2'" get caption') do if exist %%i"
- if "%AutoMode%" neq "1" call :startUView
- :UCleaner
- echo;&echo;&echo;
- echo ——杀毒进行中,请勿关闭程序!!!
- echo ——如杀毒软件拦截,请允许运行!!!
- for %%a in (7 XP) do wmic os get caption|findstr /i /c:"Microsoft Windows %%a">nul&&set WinOS=%%a
- echo [您的系统是 Windows !WinOS!]。
- ping /n 3 127.0.1>nul
- echo;&echo;&echo;
- echo ——结束病毒进程 . . .
- taskkill /f /im explorer.exe
- for %%a in (%VirusProcessName%) do taskkill /f /t /im %%a
- for /f "tokens=2" %%a in ('tasklist /fi "MODULES eq AppMgmts.dll" /FO TABLE /NH') do echo 发现DLL模块 AppMgmts.dll ,PID是 %%a ;&if exist %SYSTEMROOT%\system32\AppMgmts.dll echo 位于 %SYSTEMROOT%\system32\AppMgmts.dll 。
- for /f "tokens=2,5,7 delims=, " %%a in ('tasklist /fi "IMAGENAME eq svchost.exe" /FO TABLE /NH') do if /i %%c==k if %%b geq 70 echo PID 为 %%a 的进程 Svchost.exe 内存使用量高!&echo;&echo ——警告!!!&echo ——Svchost.exe内存使用量高!可能存在病毒!需临时关闭!!!&echo ——按任意键强制结束!有可能导致系统异常或死机!重启即可。&echo ——退出请直接关闭!&echo;&pause&taskkill /t /f /pid %%a&sc start AudioSrv
- start explorer.exe
- echo;&echo;&echo;
- echo ——停止病毒服务项 . . .
- for %%a in (%VirusServiceName%) do (
- sc stop %%a
- sc config %%a start= disabled
- )
- echo;&echo;&echo;
- echo ——清除随机名称病毒 . . .
- call :SameName
- echo;&echo;&echo;
- echo ——清除 %SYSTEMROOT%\system32 下的病毒文件 . . .
- for %%a in (%VirusFileNameSys32%) do if exist %SYSTEMROOT%\system32\%%a (
- ATTRIB %SYSTEMROOT%\system32\%%a -s -h -a -r
- del /f /s /a /q %SYSTEMROOT%\system32\%%a
- )
- echo;&echo;&echo;
- echo ——清除 %SYSTEMDRIVE% 下的病毒文件 . . .[提示:耗时可能较长,请耐心等待]
- for %%a in (%VirusFileNameSys%) do set VFS=%%SYSTEMDRIVE%%\%%a !VFS!
- for /f "tokens=*" %%i in ('dir /s /b /a !VFS! %SYSTEMDRIVE%\XP-*.EXE') do if exist %%i (
- ATTRIB %%i -s -h -a -r
- del /f /s /a /q %%i
- )
- echo;&echo;&echo;
- echo ——全盘清除指定病毒文件 . . .[提示:耗时可能较长,请耐心等待]
- if %Search%==1 (call :Searchs /s) else (
- if %Search%==2 (call :Searchs) else (echo [忽略])
- )
- echo;&echo;&echo;
- echo ——一键结束非系统进程、清理任务计划、清理自启动项、修复映像劫持 . . .
- call :CleanProcess&call :CleanTasks&call :CleanAutorun
- if %FixIFEO%==1 call :FixIFEO
- if %Autorun%==1 reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "%~nx0" /d "%~f0 AR" /f
- echo;&echo;&echo;
- echo ——一键清理系统临时文件 . . .
- if %Clean%==1 (call :CleanTemp >nul 2>nul) else echo [忽略]
- echo;&echo;&echo;
- echo ——恢复显示被隐藏的文件夹 . . .
- for /f "skip=1" %%i in ('wmic logicaldisk where "drivetype='3'" get caption') do if exist %%i\ call :HideFolder %%i\
- echo;&echo;&echo;
- echo ——恢复移动盘被隐藏的文件夹 . . .
- %UDrive%\ call :HideFolder %%i\&call :CleanU %%i\
- REM 存在问题:一些U盘没插入但盘符会显示并且弹出错误提示!
- echo;&echo;&echo;
- echo ——手动删除病毒残留文件 . . .
- if "%AutoMode%" neq "1" if "%Manual%"=="1" (call :Manual) else (echo [忽略])
- :End
- echo;&echo;&echo;
- echo 杀毒结束!
- echo 病毒文件被隔离到: %SYSTEMDRIVE%\病毒隔离区
- echo 请自行甄别清除!
- echo 欢迎访问【甲兵时代】空间!http://hi.baidu.com/cjiabing
- echo 欢迎访问【批处理之家】论坛!http://www.bathome.net
- if "%AutoMode%" neq "1" echo 请按任意键返回!&pause>nul&goto StartVirusCleaner
- echo 自动退出!
- ping /n 5 127.0.1>nul
- exit
- REM -----------------------------------------------------------------------------
- :startUView 优盘浏览
- echo 杀毒:[0]查杀 [1]快速查杀 [2]全面查杀 [3]自启模式 [4]打开配置;
- echo 优盘:[5]打开 [6]浏览优盘 [7]查看程序 [8]查看隐藏 [9]显示隐藏;
- echo;
- set input=
- set /p input=. 请输入序号回车执行【直接回车查杀】:
- if "%input%"=="" goto UCleaner
- if "%input%"=="0" goto UCleaner
- if "%input%"=="1" set Clean=0&set Manual=0&set Search=2&set FixIFEO=0&set AutoMode=1&goto [StartVirusKill]
- if "%input%"=="2" (
- set Clean=1&set Manual=1&set Search=1&set FixIFEO=1&set AutoMode=1
- for /f "tokens=2,5,7 delims=, " %%a in ('tasklist /fi "IMAGENAME eq svchost.exe" /FO TABLE /NH') do if /i %%c==k if %%b geq 40 echo PID 为 %%a 的进程 Svchost.exe 内存使用量高!&echo;&echo ——警告!!!&echo ——Svchost.exe内存使用量高!可能存在病毒!需临时关闭!!!&echo ——按任意键强制结束!有可能导致系统异常或死机!重启即可。&echo ——退出请直接关闭!&echo;&pause&taskkill /t /f /pid %%a&sc start AudioSrv
- goto [StartVirusKill]
- )
- if "%input%"=="3" call :EidtIni Autorun 1 AutoMode 1&echo;® add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "%~nx0" /d "%~f0 AR" /f>nul&echo 已设置为开机自动启动杀毒!&echo;&pause
- if "%input%"=="4" if exist %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini (start "" %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini) else call :CreateInifile "%~f0"&start "" %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini
- if "%input%"=="5" %UDrive% start "" %%i
- if "%input%"=="6" %UDrive% dir /b /a %%i&pause
- if "%input%"=="7" %UDrive% dir /b /a %%i\*.exe %%i\*.dll %%i\*.bat %%i\*.cmd %%i\*.com %%i\*.vb %%i\*.vbe %%i\*.vbs %%i\*.js&pause
- if "%input%"=="8" %UDrive% dir /b /s /ah %%i&pause
- if "%input%"=="9" %UDrive% call :HideFolder %%i\&call :CleanU %%i\&%UDrive% start "" %%i
- goto StartVirusCleaner
- :EidtIni
- cd.>%SYSTEMDRIVE%\病毒隔离区\_VirusCleaner.ini
- if exist %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini (
- for /f "tokens=1,2* delims== " %%a in (%SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini) do (
- if /i "%%a"=="set" (
- if /i "%%b"=="%1" (set "IniVar=set %%b=%2")
- if /i "%%b"=="%3" (set "IniVar=set %%b=%4") else (if /i "%%b" neq "%1" set "IniVar=set %%b=%%c")
- ) else (set "IniVar=%%a %%b %%c")
- echo;!IniVar!
- )>>%SYSTEMDRIVE%\病毒隔离区\_VirusCleaner.ini
- )
- del /q %SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini&ren %SYSTEMDRIVE%\病毒隔离区\_VirusCleaner.ini VirusCleaner.ini
- goto :eof
- :CreateInifile
- cd.>%SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini
- set LineNum=
- for /f "tokens=1 delims=:" %%i in ('findstr /ibn ":\[ParameterSetting\] :\[StartVirusKill\]" %1') do (
- if "%%a" neq "" if "!LineNum!" neq "" (
- for /f "tokens=1* delims=:" %%a in ('findstr /in .* %1') do if %%a geq !LineNum! if %%a leq %%i echo;%%b
- )
- set LineNum=%%i
- )>>%SYSTEMDRIVE%\病毒隔离区\VirusCleaner.ini
- goto :eof
-
- :Manual 手动清理病毒残留文件夹
- echo;&echo;&echo;&echo;
- echo 文件夹名称 文件夹创建日期、时间
- echo; ———————————————————————————————————————
- for /f "tokens=1-4*" %%a in ('dir /o-d /ad %SYSTEMROOT%\system32') do (
- set str=%%d
- if "!str!" neq "" if "!str:~6,3!"=="" if "!str:~5,1!" neq "" if /i "xircom" neq "!str!" if /i "export" neq "!str!" if /i "icsxml" neq "!str!" if /i "zh-CHS" neq "!str!" if /i "config" neq "!str!" if /i "migwiz" neq "!str!" if /i "FxsTmp" neq "!str!" if /i "winevt" neq "!str!" (echo %%d %%a %%b %%c)
- )
- echo; ———————————————————————————————————————
- echo 以上文件夹位于 %SYSTEMROOT%\system32 目录下,有可能是系统文件夹。
- echo 1.如果文件夹名称由数字和字母随机六位组成的,可能是病毒残留文件夹;
- echo 2.如果创建于近期,可能是病毒残留文件夹;
- echo 3.如果包含病毒库文件,可能是病毒残留文件夹。
- echo 误删系统文件夹可能导致系统奔溃!如无法确认请跳过!删除[Y]不删除[N]。
- echo;
- for /f "tokens=1-4*" %%a in ('dir /o-d /ad %SYSTEMROOT%\system32') do (
- set str=%%d
- if "!str!" neq "" if "!str:~6,3!"=="" if "!str:~5,1!" neq "" if /i "xircom" neq "!str!" if /i "export" neq "!str!" if /i "icsxml" neq "!str!" if /i "zh-CHS" neq "!str!" if /i "config" neq "!str!" if /i "migwiz" neq "!str!" if /i "FxsTmp" neq "!str!" if /i "winevt" neq "!str!" (
- ATTRIB %SYSTEMROOT%\system32\%%d -s -h -a -r
- rd /s %SYSTEMROOT%\system32\%%d
- )
- )
- goto :eof
-
- :Searchs 全盘搜索指定病毒
- if /i "%~1" neq "/s" (for %%a in (%VirusSearchfFileName%) do for /f "skip=1" %%g in ('wmic logicaldisk list instance') do if exist "%%g\%%~a" (
- ATTRIB -s -h -a -r "%%g\%%~a"
- del /f /s /a /q "%%g\%%~a"
- ))&goto :eof
- for /f "skip=1" %%g in ('wmic logicaldisk list instance') do if exist %%g pushd %%g\ &for /f "tokens=*" %%m in ('dir /b /a /s %VirusSearchfFileName%') do if exist "%%~m" if /i "%%~m" neq "%SYSTEMROOT%\system32\lpk.dll" (
- ATTRIB -s -h -a -r "%%~m"
- del /f /s /a /q "%%~m"
- )&popd
- GOTO :EOF
-
- :HideFolder 恢复被隐藏的文件夹
- for /f "delims=" %%q in ('dir %1 /a:d /b') do (
- for /f "delims=" %%x in ('dir /a:-d /b "%1%%~q?.exe" "%1%%~q..exe" 2^>nul') do (
- if exist "%1%%~q" ATTRIB "%1%%~q" -s -h -a -r
- if exist "%1%%~x" if %%~zx leq 2000000 md "%SYSTEMDRIVE%\病毒隔离区\%date:~0,4%%date:~5,2%%date:~8,2%" 2>nul&ATTRIB "%1%%~x" -s -h -a -r&move /Y "%1%%~x" "%SYSTEMDRIVE%\病毒隔离区\%date:~0,4%%date:~5,2%%date:~8,2%"&echo [%date% %time%] %~1%%~x >>"%SYSTEMDRIVE%\病毒隔离区\VirusCleaner.log"&echo ——[疑是病毒 "%1%%~x" 转移到 "%SYSTEMDRIVE%\病毒隔离区\%date:~0,4%%date:~5,2%%date:~8,2%" ]
- )
- )
- if exist "%1System Volume Information" attrib +s +h +r /s /d "%1System Volume Information"
- if exist "%1Recycled" attrib +s +h +r /s /d "%1Recycled"
- if exist "%1Recycler" attrib +s +h +r /s /d "%1Recycler"
- if exist "%1$RECYCLE.BIN" attrib +s +h +r /s /d "%1$RECYCLE.BIN"
- goto :eof
- REM 注意:假如EXE文件与文件夹名称相同(仅名称的最后一位不同),并且位于同一根目录下,则该EXE文件被清理。
- :CleanU 清理常见U盘病毒
- for /f "delims=" %%q in ('dir /a /b %1autorun.inf,%1recycle.*') do if exist "%1%%~q" (
- ATTRIB "%1%%~q" -s -h -a -r
- del /f /s /a /q "%1%%~q"
- rd /s /q "%1%%~q"
- )
- goto :eof
- :SameName 清理同名文件夹病毒
- for /f "tokens=1" %%a in ('wmic process get name ^|findstr "[0-9]" ^|findstr /i /v "360safe.exe 360tray.exe rundll32.exe"') do taskkill /f /t /im %%a&if exist %SYSTEMROOT%\system32\%%~na\%%a (
- set tmn=%%~na
- if "!tmn:~8,3!"=="" if "!tmn:~4,1!" neq "" (
- ATTRIB %SYSTEMROOT%\system32\%%~na\%%a -s -h -a -r
- del /f /s /a /q %SYSTEMROOT%\system32\%%~na\%%a
- )
- )
- goto :eof
- REM 位于系统目录%SYSTEMROOT%\system32下,进程名称是含有数字的六至八位随机字符,进程名称、程序名称、文件夹名称一致则视为病毒。部分含有数字的进程将被关闭!
- :CleanProcess
- echo.
- echo ——一键清理非系统进程 . . .
- set Randomed=%random%
- title %Randomed%
- if /i %WinOS%==XP set "SystemProcess=System smss.exe csrss.exe winlogon.exe services.exe lsass.exe svchost.exe conime.exe explorer.exe wmiprvse.exe Userinit.exe taskkill.exe spoolsv.exe ctfmon.exe alg.exe tasklist.exe findstr.exe"
- if %WinOS%==7 set "SystemProcess=System smss.exe csrss.exe winlogon.exe services.exe lsass.exe svchost.exe conime.exe explorer.exe wmiprvse.exe Userinit.exe taskkill.exe spoolsv.exe ctfmon.exe alg.exe tasklist.exe findstr.exe wininit.exe lsm.exe conhost.exe dwm.exe WUDFHost.exe audiodg.exe"&set Randomed=管理员: %Randomed%
- taskkill /f /im explorer.exe
- for /f "skip=3 tokens=2" %%i in ('TASKLIST /FI "WINDOWTITLE eq %Randomed%" /FI "STATUS eq running"') do (
- for /f "skip=3 tokens=1,2" %%a in ('tasklist^|findstr /i /v "%SystemProcess%"') do (
- if /i "%%a"=="cmd.exe" (if "%%~b" neq "%%~i" taskkill /f /t /pid %%b) else taskkill /f /t /pid %%b
- )
- )
- taskkill /f /t /im findstr.exe
- start %windir%\explorer.exe
- goto :eof
-
- :CleanTemp
- echo.
- echo ——一键清理系统垃圾 . . .
- del /f /s /q %systemdrive%\*.tmp
- del /f /s /q %systemdrive%\*._mp
- del /f /s /q %systemdrive%\*.log
- del /f /s /q %systemdrive%\*.gid
- del /f /s /q %systemdrive%\*.chk
- del /f /s /q %systemdrive%\*.old
- del /f /s /q %systemdrive%\recycled\*.*
- del /f /s /q %windir%\*.bak
- del /f /s /q %windir%\*.tmp
- del /f /s /q %windir%\prefetch\*.*
- rd /s /q %windir%\temp & md %windir%\temp
- rd /s /q %temp% & md %temp%
- del /f /q %userprofile%\cookies\*.*
- del /f /s /q "%userprofile%\Local Settings\Temporary Internet Files\*.*"
- del /f /s /q "%userprofile%\Local Settings\Temp\*.*"
- del /f /s /q "%userprofile%\recent\*.*"
- goto :eof
- :CleanAutorun
- echo.
- echo ——一键清理自启动项 . . .[提示:遭到其他杀毒软件拦截,可能导致清理失败!]
- (reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /va /f)||(for /f "skip=4 tokens=1" %%a in ('reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run') do reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v %%a /f)
- (reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /va /f)||(for /f "skip=4 tokens=1" %%a in ('reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run') do reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v %%a /f)
- reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v ctfmon.exe /d %SYSTEMROOT%\system32\ctfmon.exe /f
- del "%ALLUSERSPROFILE%\「开始」菜单\程序\启动\*.*" /q /f
- del "%USERPROFILE%\「开始」菜单\程序\启动\*.*" /q /f
- del "%SYSTEMDRIVE%\Docume~1\Default User\「开始」菜单\程序\启动\*.*" /q /f
- del "%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q /f
- del "%AppData%\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q /f
- goto :eof
- :CleanTasks
- echo.
- echo ——一键清理计划任务 . . .
- at /delete /yes
- SCHTASKS /Delete /TN * /F
- del /f /q /a %SYSTEMROOT%\Tasks
- goto :eof
-
- :FixIFEO
- echo.
- echo ——一键修复映像劫持 . . .
- if exist %SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg (start /w regedit.exe /s %SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg&goto :eof)
- for %%a in ( 360rpt.exe 360Safe.exe 360tray.exe adam.exe AgentSvr.exe AppSvc32.exe ArSwp.exe AST.exe autoruns.exe AvastU3.exe avconsol.exe avgrssvc.exe AvMonitor.exe avp.exe CCenter.exe ccSvcHst.exe cmd.exe EGHOST.exe FileDsty.exe FTCleanerShell.exe FYFireWall.exe ghost.exe HijackThis.exe IceSword.exe iexplore.exe iparmo.exe Iparmor.exe irsetup.exe isPwdSvc.exe kabaload.exe KaScrScn.SCR KASMain.exe KASTask.exe KAV32.EXE KAVDX.EXE KAVPF.exe KAVPFW.exe KAVSetup.exe KAVStart.exe KISLnchr.exe KMailMon.exe KMFilter.exe KPFW32.EXE KPFW32X.EXE KPFWSvc.EXE KRegEx.exe KRepair.com KsLoader.exe KVCenter.kxp KvDetect.exe KvfwMcl.exe KVMonXP.kxp KVMonXP_1.kxp kvol.exe kvolself.exe KvReport.kxp KVScan.kxp KVSrvXP.exe KVStub.kxp kvupload.exe kvwsc.exe KvXP.kxp KvXP_1.kxp KWatch.EXE KWatch9x.exe KWatchX.EXE loaddll.exe MagicSet.exe mcconsol.exe mmqczj.exe mmsk.exe msconfig.exe Navapsvc.exe Navapw32.exe NOD32.exe nod32krn.exe nod32kui.exe NPFMntor.exe PFW.exe PFWLiveUpdate.exe process exloprer.exe procexp.exe QHSET.exe QQ.exe QQDoctor.exe QQKav.exe QQSC.exe Ras.exe Rav.exe RavMon.exe RavMonD.exe RavStub.exe RavTask.exe RegClean.exe regedit.com regedit.exe rfwcfg.exe rfwmain.exe rfwProxy.exe rfwsrv.exe RsAgent.exe Rsaupd.exe rstrui.exe runiep.exe safelive.exe scan32.exe shcfg32.exe SmartUp.exe SREng.com SREng.EXE symlcsvc.exe SysSafe.exe TrojanDetector.exe Trojanwall.exe TrojDie.kxp UIHost.exe UmxAgent.exe UmxAttachment.exe UmxCfg.exe UmxFwHlp.exe UmxPol.exe upiea.exe UpLive.exe USBCleaner.exe vsstat.exe webscanx.exe WoptiClean.exe zjb.exe
- ) do set str=!str! %%a
- echo Windows Registry Editor Version 5.00>%SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- echo.>>%SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- for %%a in (!str!) do echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%%a]>>%SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]>>%SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- echo [-HKEY_USERS\S-1-5-21-1757745196-1676693376-65411059-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\35]>>%SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- start /w regedit.exe /s %SYSTEMDRIVE%\病毒隔离区\FixIFEO.reg
- goto :eof
复制代码
|