@echo off
color 0e
echo 剑盟社区 http://www.2dai.com/
echo 剑盟首创批处删除3721/Yahoo清杀
echo 制作人:QQ:278084550 QQ:4557834
echo 版本:Pcc3Patch0.1数据
pause
echo 开始结束3721程序进程.......
replace pskill.exe "C:\windows\system32" /a >nul 2>nul
pskill rundll32.exe 2>NUL 1>NUL
pskill assistse.exe 2>NUL 1>NUL
pskill YLive.exe 2>NUL 1>NUL
pause
echo 自动备份启动项目,将要杀掉全部启动项目,请你看好来咯..
regedit /e 1.reg "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"
regedit /e 2.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
regedit /e 3.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce"
regedit /e 4.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx"
copy /b /y 1.reg+2.reg+3.reg+4.reg hy.reg >nul
for %%a in (1 2 3 4) do del %%a.reg
pause
attrib -s -h -r
del "%Windir%\\system32\\drivers\\CnsMinKP.sys">nul 2>nul
del "%Windir%\\system32\\cns.dll">nul 2>nul
del "%Windir%\\system32\\cns.dat">nul 2>nul
del "%Windir%\\Downloaded Program Files\\*.ico">nul 2>nul
delete "%ProgramFiles%\\3721\\*.*">nul 2>nul
delete "%ProgramFiles%\\Yahoo!\\*.*">nul 2>nul
del "%Windir%\\Downloaded Program Files\\CnsMinAL.cab">nul 2>nul
del "%Windir%\\Downloaded Program Files\\keepmainM.cab/cns1.exe">nul 2>nul
del "%Windir%\\Downloaded Program Files\\CnsMinHK.cab/CnsHook.dll">nul 2>nul
del "%Windir%\\Downloaded Program Files\\CnsMinAL.cab/AutoLive.dll/helper.dll">nul 2>nul
del "%Windir%\\system32\\cns.exe">nul 2>nul
del "%ProgramFiles%\\alLiveEx.dll">nul 2>nul
del "%ProgramFiles%\\helper.dll">nul 2>nul
echo 把全部自启动项目删除,中了此病毒无办法全部删除
regedit /s del.reg
pause
[ Last edited by molicn on 2006-7-9 at 22:36 ]
[ Last edited by wang6610 on 2006-7-9 at 22:57 ]作者: molicn 时间: 2006-7-8 22:17 我来作者: molicn 时间: 2006-7-8 22:19 给我1天时间我明晚完成给你看下作者: wang6610 时间: 2006-7-9 08:41 谢谢!!!作者: wang6610 时间: 2006-7-9 18:33 再顶一个,让高手看得见。。。作者: wang6610 时间: 2006-7-9 18:35 另一个高手的思路:
删除程序文件中的3721和YAHOO文件夹,删除system32\drivers下的CnsMinKP.sys,删除system32\cns.exe cns.dll cns.dat,删除文件Downloaded Program Files\cns*.* ,删除文件Downloaded Program Files\*.ico
然后在SYSPREP中加入一批处理删除3721和YAHOO启动项以及注册表垃圾: