只要有兩個批次檔就解決了... ?<yq 2`\4O
MNf @HG
第一個檔將下面的文字剪下貼上記事本再把檔名存成 kavo1.bat kTiPZZI
THbtu*El
-------------------------------------------------------------------------------------------------------------------- e0|_Z])D
@echo off vzohq1r5
cls Kixr6\
echo. IB#iJ#,
echo 自動刪除KAVO病毒 第1個步驟 veX"CY`hn
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "kava" /f >nul 2>nul A'~%_}
echo. u6iU[5
echo 1.刪除個磁碟中的autorun.inf及ntdelect.com的病毒檔 ]M+VSU
echo. R%Ui6dCLo
echo 請按任意鍵以開始做這個動作..... &*G5J7%w
pause >nul 2>nul BrlzN='j}
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( 2qs>Bshf
attrib -r -s -h -a %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&attrib -r -s -h -a %%a:\ntdelect.com >nul 2>nul {)
:%WnM9
del %%a:\autorun.inf /q /f >nul 2>nul&&echo.&&echo.&&del %%a:\nddelect.com /q /f >nul 2>nul ) A9\]3 LY
echo. r/NSD$-n
cls lZ|L2Yg3uB
echo autorun.inf及ntdelect.com 的病毒檔刪除完成 w5F4"nl#O}
echo. (C8 U
echo. R)0N0gH
echo. "+=Pp
echo 2.建立名稱為autorun.inf的資料夾,防止病毒再度寫入 2
;JQX!
echo 屬性順便改成「唯讀、隱藏、系統」 z;i4N3-:
echo. QX[Djz0H8
echo 請按任意鍵以開始做這個動作..... rh@r\H@j
pause >nul 2>nul 4&Byl85q
pause >nul 2>nul i+g~ Uj}h
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( 8{dEpV*
del %%a:\autorun.inf /q /f >nul 2>nul&del %%a:\nddelect.com /q /f >nul 2>nul "!O1j
r;
md %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&attrib +r +s +h %%a:\autorun.inf >nul 2>nul ) yL6^\x
echo 完成autorun.inf資料夾的建立(可用attrib autorun.inf的指令看到) tJNIr5o
echo. B
MM--y@
echo. mzWP8Hlw
echo. 8-m
3e
echo 最後請『重新開機』再執行第2個步驟的批次檔 4:7m K/Z
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... _T5)n=|
pause >nul 2>nul zvY+R\,in
pause >nul 2>nul *RWm47
6.5wZN9<|
Dzl;-]S
----------------------------------------------------------------------------------------------------------------- 9XLFHV("
hIYTe
第二個檔做法一樣...改成kavo2.bat +/rH(Ni
2&Jdf
------------------------------------------------------------------------------------------------------------------- 6/Fzco#N
@echo off WC,+Cn e
cls 9Q;c,]
echo. lFSe?X^
echo 自動刪除KAVO病毒 第2個步驟(前提執行過第1個步驟後重開機) p\p\q(S">
echo 如未執行過第1個步驟請按「CTRL+C」結束這個動作 IA&L]
echo. Bux [6O%
echo 3.將被鎖定的隱藏檢視功能開啟(登錄檔的部份) bzN-*3YE=
echo. Sh6JF574T
echo 請按任意鍵以開始做這個動作..... R6-n IY,
pause >nul 2>nul &MZ$j46
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CheckedValue" /t REG_DWORD /d 00000001 /f >nul 2>nul 4+$b~u
echo. ltB.Q
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "DefaultValue" /t REG_DWORD /d 00000002 /f >nul 2>nul OLGBt
echo.
D_mL,w
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CHKeyRoot" /t REG_DWORD /d 80000001 /f >nul 2>nul fKC3-zm
echo. %J:SO_6
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "ValueName" /t REG_SZ /d Hidden /f >nul 2>nul u]
:m"LM
echo. Oa;X+
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Text" /t REG_SZ /d "@shell32.dll,-30500" /f >nul 2>nul J:uW`R
echo. Uoya3#4 G
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Type" /t REG_SZ /d radio /f >nul 2>nul 8l}1c=A}Vi
echo. )"f
N!9,F
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "RegPath" /t REG_SZ /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f >nul 2>nul vZ/6\Cz
echo. u2oKH{/z
cls N#lDW~e'
echo 已修復無法開啟檢視隱藏檔的功能 V
f-a'K&
echo 請到資料夾中的資料夾選項去開啟檢視隱藏的功能(有需要就開,不需要就別開) UobyK3.%
echo. gP+fN$5'd
echo 4.刪除kavo.exe的病毒主程式 !`!| Zw
echo. kB5.(O
attrib -s -h -r "C:\WINDOWS\system32\kav*.*" >nul 2>nul ~=R SKyzt
del "C:\WINDOWS\system32\kav*.*" >nul 2>nul zhY+x<-
attrib -s -h -r "C:\ntdelect.com" >nul 2>nul ;[RZ0Uy=
del "C:\ntdelect.com" >nul 2>nul Q f(p~a(d
attrib -s -h -r "C:\WINDOWS\fly3*.*" >nul 2>nul d
GP*O
del "C:\WINDOWS\fly3*.*" >nul 2>nul !n^OM?.4
attrib -r -s -h -a "c:\found.???" /S /D >nul 2>nul _=|vgc
del "c:\found.???\*.*" /s /q /f >nul 2>nul ?`J[[",
echo. zSb PW6U
echo 刪除完成,kavo的病毒已成功解除! u+{a8=
echo. &HSq(te
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... GKcv<G208
pause >nul 2>nul }%D^8>S
pause >nul 2>nul `O'`eY1f
]5%/3P,/
------------------------------------------------------------------------------------------------------------------------------ +>4;Z d!@d
WVLHfkN
最後再把這兩個檔放到C槽根目錄下...點第一個檔...會提示重開機...重開後再點第二個檔...按照說明做...這樣就行了... ;V<fB/S.=+
3N_"rNKD
祝大家解毒愉快!~~