只要有兩個批次檔就解決了... vsLn@k3
/&dC? bY
第一個檔將下面的文字剪下貼上記事本再把檔名存成 kavo1.bat zYF'XB]4
!AP|ozkL
-------------------------------------------------------------------------------------------------------------------- e,8C}
2
@echo off m<r.sq&;
cls ;J2=6np
echo. Zj!S('hSY
echo 自動刪除KAVO病毒 第1個步驟 !d%OoRSU'
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "kava" /f >nul 2>nul 1+Ja4`o,iS
echo. P4ot,Q4
echo 1.刪除個磁碟中的autorun.inf及ntdelect.com的病毒檔 efRa|7!HK
echo. Z}$.Tm
echo 請按任意鍵以開始做這個動作..... M
HlP)'
pause >nul 2>nul GS \-
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( cfa#a!Y4
attrib -r -s -h -a %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&attrib -r -s -h -a %%a:\ntdelect.com >nul 2>nul 03AYW)"}M
del %%a:\autorun.inf /q /f >nul 2>nul&&echo.&&echo.&&del %%a:\nddelect.com /q /f >nul 2>nul ) x>p=1(L
echo. sw8Ic\vT
cls qdvGBdF
echo autorun.inf及ntdelect.com 的病毒檔刪除完成 H Viu7kue`
echo. xL=g(FN(6L
echo. ;@
%~eIlu
echo. M\>y&'J-
echo 2.建立名稱為autorun.inf的資料夾,防止病毒再度寫入 qeH#c=DQ
echo 屬性順便改成「唯讀、隱藏、系統」 j#<#o:If
echo. #^%Rk'W
echo 請按任意鍵以開始做這個動作..... 0'c<EJ
pause >nul 2>nul fb&K.6"
pause >nul 2>nul *.n9D
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( DyYl97+Z?
del %%a:\autorun.inf /q /f >nul 2>nul&del %%a:\nddelect.com /q /f >nul 2>nul ) l0=jb
md %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&attrib +r +s +h %%a:\autorun.inf >nul 2>nul ) \/S?.P#L~
echo 完成autorun.inf資料夾的建立(可用attrib autorun.inf的指令看到) f)?s.DvUB
echo. kplyZ
echo. q J@XVN4
echo. 0Eo*C9FP~
echo 最後請『重新開機』再執行第2個步驟的批次檔 H [R|U
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... kYmkKl_
pause >nul 2>nul Nq9@^ E-{M
pause >nul 2>nul ro|dB
JY4 +MApN
NIQNzq?a^
----------------------------------------------------------------------------------------------------------------- g.iiT/b
HT[<~c
第二個檔做法一樣...改成kavo2.bat 65)/|j+
z|<6y~5,
------------------------------------------------------------------------------------------------------------------- 5)AMl)
@echo off 9V9K3xWn
cls F$^RM3
echo. dNU i|IYm$
echo 自動刪除KAVO病毒 第2個步驟(前提執行過第1個步驟後重開機)
+ZQf$@+
echo 如未執行過第1個步驟請按「CTRL+C」結束這個動作 )CD4k:bm
echo. w/IYQC\v
echo 3.將被鎖定的隱藏檢視功能開啟(登錄檔的部份) >7V96jL$Y
echo. "v@Y[QI
echo 請按任意鍵以開始做這個動作..... jhgS@g=@ZC
pause >nul 2>nul opU=49b
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CheckedValue" /t REG_DWORD /d 00000001 /f >nul 2>nul bA!n;
echo. EmNJ_xY
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "DefaultValue" /t REG_DWORD /d 00000002 /f >nul 2>nul 3`.*~qW
echo. C~-x637/
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CHKeyRoot" /t REG_DWORD /d 80000001 /f >nul 2>nul -@L7!,j
echo. FnxPM`Zx
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "ValueName" /t REG_SZ /d Hidden /f >nul 2>nul C# zYZ JZ
echo. epN>;e z
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Text" /t REG_SZ /d "@shell32.dll,-30500" /f >nul 2>nul mxD]`F
echo. q8A ;%.ZLG
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Type" /t REG_SZ /d radio /f >nul 2>nul zVt1Ta:j
echo. {g9*t}l4
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "RegPath" /t REG_SZ /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f >nul 2>nul xVxN
@[
echo. Gh%R4)}
cls s qXwDy+.
echo 已修復無法開啟檢視隱藏檔的功能 ,J6t
1V
echo 請到資料夾中的資料夾選項去開啟檢視隱藏的功能(有需要就開,不需要就別開) :+_uyp2V
echo. 8Z|A'M
echo 4.刪除kavo.exe的病毒主程式 b>h
L*9
echo. a yYl3
attrib -s -h -r "C:\WINDOWS\system32\kav*.*" >nul 2>nul ~xLo0EV"
del "C:\WINDOWS\system32\kav*.*" >nul 2>nul z0H+Or
attrib -s -h -r "C:\ntdelect.com" >nul 2>nul IayF<y,8
del "C:\ntdelect.com" >nul 2>nul s6F0&L;N&
attrib -s -h -r "C:\WINDOWS\fly3*.*" >nul 2>nul 2T?8{yO7
del "C:\WINDOWS\fly3*.*" >nul 2>nul 2FN E ;y(
attrib -r -s -h -a "c:\found.???" /S /D >nul 2>nul C2CR#b=)i
del "c:\found.???\*.*" /s /q /f >nul 2>nul {%_D>y
echo. 2:RFPK
echo 刪除完成,kavo的病毒已成功解除!
2g~W})e
echo. Wf3{z
D~
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... 9?q ^yy
pause >nul 2>nul DS+BX`i%#p
pause >nul 2>nul {Hie%2V
s",G
w]8
------------------------------------------------------------------------------------------------------------------------------ i%GiWanG
<`WDNi$Y
最後再把這兩個檔放到C槽根目錄下...點第一個檔...會提示重開機...重開後再點第二個檔...按照說明做...這樣就行了... /oZvm
/eT9W[a
祝大家解毒愉快!~~