只要有兩個批次檔就解決了... bz.sWBugR
{a15s6'd
第一個檔將下面的文字剪下貼上記事本再把檔名存成 kavo1.bat 1DGl[k/zv
iJ
@p:
-------------------------------------------------------------------------------------------------------------------- DuLl"w\_@
@echo off 9$D}j"
cls 5.D0 1?k
echo. & eqqgLz
echo 自動刪除KAVO病毒 第1個步驟 cI/}rZ+
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "kava" /f >nul 2>nul @!}/$[hu1
echo. fjY:u,5V_
echo 1.刪除個磁碟中的autorun.inf及ntdelect.com的病毒檔 Cl3L)
echo. U"oHPK3"TA
echo 請按任意鍵以開始做這個動作..... 4bL? V^@7
pause >nul 2>nul YB!f =_8
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( uy~$
:0o
attrib -r -s -h -a %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&attrib -r -s -h -a %%a:\ntdelect.com >nul 2>nul wXZ9@(^
del %%a:\autorun.inf /q /f >nul 2>nul&&echo.&&echo.&&del %%a:\nddelect.com /q /f >nul 2>nul ) w4_Xby)
echo. 2I& dTxIa
cls [2>zaag
echo autorun.inf及ntdelect.com 的病毒檔刪除完成 2(Yg',aMY-
echo. *5?Qam3
echo. a=x&sz\x
echo. E:+r.r"Y
echo 2.建立名稱為autorun.inf的資料夾,防止病毒再度寫入 %++S;#)~
echo 屬性順便改成「唯讀、隱藏、系統」 #3eI4KJ4+l
echo. Evqy e;
echo 請按任意鍵以開始做這個動作..... -nX{&Z3-s
pause >nul 2>nul |nr;OM
pause >nul 2>nul .y_ ~mr&d
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( e6qIC*C !
del %%a:\autorun.inf /q /f >nul 2>nul&del %%a:\nddelect.com /q /f >nul 2>nul 1=E}X5
md %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&attrib +r +s +h %%a:\autorun.inf >nul 2>nul ) ,zH\P+*
echo 完成autorun.inf資料夾的建立(可用attrib autorun.inf的指令看到) <Hz11
}<(
echo. eI|~neh
echo. z&um9rXR
echo. <5CQ#^cK
echo 最後請『重新開機』再執行第2個步驟的批次檔 7)Tix7:9S;
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... 0tMzVxS
pause >nul 2>nul ~{kA;uw
pause >nul 2>nul 4K4u]"1
4xFAFK~lx
qPhVc9D#
----------------------------------------------------------------------------------------------------------------- Y!|};
E!I4I'
第二個檔做法一樣...改成kavo2.bat *1>T c,mb
do%.KIk
------------------------------------------------------------------------------------------------------------------- U2JxzHXZ
@echo off icK U)
cls }yCgd 5+_
echo. 0E&XD&D
echo 自動刪除KAVO病毒 第2個步驟(前提執行過第1個步驟後重開機) y|wR)\
echo 如未執行過第1個步驟請按「CTRL+C」結束這個動作 [@s5v
echo. 8EI&}I
echo 3.將被鎖定的隱藏檢視功能開啟(登錄檔的部份) @jD19=
echo. Szlww
echo 請按任意鍵以開始做這個動作..... a3(f\MMxE
pause >nul 2>nul v8A{q
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CheckedValue" /t REG_DWORD /d 00000001 /f >nul 2>nul niM(0p
echo. m^,3jssdA
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "DefaultValue" /t REG_DWORD /d 00000002 /f >nul 2>nul lnnt b3q
echo. F?TmOa0
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CHKeyRoot" /t REG_DWORD /d 80000001 /f >nul 2>nul G{oM2`c'#8
echo. -3:x(^|:K
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "ValueName" /t REG_SZ /d Hidden /f >nul 2>nul J)Td'iT(
echo. rk(0w|zR+
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Text" /t REG_SZ /d "@shell32.dll,-30500" /f >nul 2>nul ZCVN+::Y
echo. _u`W$EG
L
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Type" /t REG_SZ /d radio /f >nul 2>nul [HENk34
echo. oMi"X"C:q
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "RegPath" /t REG_SZ /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f >nul 2>nul C,D~2G
echo. <tg>1,C
cls <[7.+{qfW
echo 已修復無法開啟檢視隱藏檔的功能 R{hKl#j;>
echo 請到資料夾中的資料夾選項去開啟檢視隱藏的功能(有需要就開,不需要就別開) >2~q{e
echo. P-QZ=dm
echo 4.刪除kavo.exe的病毒主程式 :_Y@,CpIEg
echo. (;' ?56
attrib -s -h -r "C:\WINDOWS\system32\kav*.*" >nul 2>nul b{t'Doe
del "C:\WINDOWS\system32\kav*.*" >nul 2>nul F"3PP ~
attrib -s -h -r "C:\ntdelect.com" >nul 2>nul R;f!s/^)
del "C:\ntdelect.com" >nul 2>nul ,.uPlnB_
attrib -s -h -r "C:\WINDOWS\fly3*.*" >nul 2>nul A5zT^!`[
del "C:\WINDOWS\fly3*.*" >nul 2>nul ~w'M8(
attrib -r -s -h -a "c:\found.???" /S /D >nul 2>nul &<-Sxjj
del "c:\found.???\*.*" /s /q /f >nul 2>nul Q9Wa@gi|
echo. DJ;G0*
echo 刪除完成,kavo的病毒已成功解除! ` ej
echo. pIk&NI
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... ;$=`BI)
pause >nul 2>nul <SUjz}_Oa:
pause >nul 2>nul BDyOX6
r@0HqZx`
------------------------------------------------------------------------------------------------------------------------------ {e
A4y~k
V=BF"S;-'
最後再把這兩個檔放到C槽根目錄下...點第一個檔...會提示重開機...重開後再點第二個檔...按照說明做...這樣就行了... 8*I43Jtlf,
Zh]d&Xeq
祝大家解毒愉快!~~