只要有兩個批次檔就解決了... (NJ.\m
eX!yIqAR
第一個檔將下面的文字剪下貼上記事本再把檔名存成 kavo1.bat 2 &_>2"=<@
yUO%@;
-------------------------------------------------------------------------------------------------------------------- f;Ijl 0d@
@echo off >Ad`_g6Wew
cls 5N bq9YY
echo. c>+68<H
echo 自動刪除KAVO病毒 第1個步驟 U9awN&1([
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "kava" /f >nul 2>nul t3K9 |8<
echo. 4-$kcwA
echo 1.刪除個磁碟中的autorun.inf及ntdelect.com的病毒檔 [
<k&]Kv
echo. uX&h~qE/
echo 請按任意鍵以開始做這個動作..... TD4
n%k.
pause >nul 2>nul cFuQ>xR1
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( SbsdunW+?
attrib -r -s -h -a %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&attrib -r -s -h -a %%a:\ntdelect.com >nul 2>nul mGoC8t}iP
del %%a:\autorun.inf /q /f >nul 2>nul&&echo.&&echo.&&del %%a:\nddelect.com /q /f >nul 2>nul ) 4!
F$nmG)
echo. -Y N(j\
cls [[]NnWJ
echo autorun.inf及ntdelect.com 的病毒檔刪除完成 -OKXfN]
echo. z:)*Aobwv
echo. )5o6*(Y
echo. hl DU.k
echo 2.建立名稱為autorun.inf的資料夾,防止病毒再度寫入 <\d2)Iv
echo 屬性順便改成「唯讀、隱藏、系統」 blaXAqe
echo. :cP u
echo 請按任意鍵以開始做這個動作..... UyF;sw
pause >nul 2>nul \oP
pause >nul 2>nul q'X#F8v
for %%a in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do ( DnF|wS
del %%a:\autorun.inf /q /f >nul 2>nul&del %%a:\nddelect.com /q /f >nul 2>nul ye| 2gH
md %%a:\autorun.inf >nul 2>nul&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&echo.&&attrib +r +s +h %%a:\autorun.inf >nul 2>nul ) V<KjKa+sG
echo 完成autorun.inf資料夾的建立(可用attrib autorun.inf的指令看到) h{?f
uoZj%
echo. M IU B]
echo. =]<X6!0mR
echo. b1Ba}
echo 最後請『重新開機』再執行第2個步驟的批次檔 >vuR:4B
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... 8BnsYy)j
pause >nul 2>nul `3dGn.M
pause >nul 2>nul !nF.whq
P_
b8_ydU
&tlU.Whk+
----------------------------------------------------------------------------------------------------------------- `>k7^!Ds
Dh9C9<Ta:
第二個檔做法一樣...改成kavo2.bat k_ijVfI9
|b|bL 7nx
------------------------------------------------------------------------------------------------------------------- VQ4rEO=t
@echo off H$)otDOE
cls {
b7%Zd3-
echo. 257q%"
echo 自動刪除KAVO病毒 第2個步驟(前提執行過第1個步驟後重開機) H`jvT]
echo 如未執行過第1個步驟請按「CTRL+C」結束這個動作 qmbhx9V
echo. l gTw>r
echo 3.將被鎖定的隱藏檢視功能開啟(登錄檔的部份) V(6Ql
j7
echo. eu?DSad
echo 請按任意鍵以開始做這個動作..... 6Vy4]jdT5
pause >nul 2>nul M7\K iQd
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CheckedValue" /t REG_DWORD /d 00000001 /f >nul 2>nul -!:h]
echo. v^1n.l %E
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "DefaultValue" /t REG_DWORD /d 00000002 /f >nul 2>nul r_M5:Rz
echo. JS0957K
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CHKeyRoot" /t REG_DWORD /d 80000001 /f >nul 2>nul <|4L+?_(&
echo. ^uWj#
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "ValueName" /t REG_SZ /d Hidden /f >nul 2>nul hO4* X
echo. >&uR=Yd
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Text" /t REG_SZ /d "@shell32.dll,-30500" /f >nul 2>nul jMQ7^(9-
echo. eLN[`hJ
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "Type" /t REG_SZ /d radio /f >nul 2>nul Rln@9muXA
echo. ]ag^~8bG
@
reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "RegPath" /t REG_SZ /d "Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /f >nul 2>nul CeW}zkcT
echo. 7?"-NrW~
cls ;@G5s+<l
echo 已修復無法開啟檢視隱藏檔的功能 DjQgF=;
echo 請到資料夾中的資料夾選項去開啟檢視隱藏的功能(有需要就開,不需要就別開) glgXSOj
echo. 7G 5VwO
echo 4.刪除kavo.exe的病毒主程式 PBp+(o-
echo. ,ku3;58O<
attrib -s -h -r "C:\WINDOWS\system32\kav*.*" >nul 2>nul >J_%'%%f
del "C:\WINDOWS\system32\kav*.*" >nul 2>nul !DNk!]|
attrib -s -h -r "C:\ntdelect.com" >nul 2>nul b<"LUM*;
del "C:\ntdelect.com" >nul 2>nul +U*:WKdI?
attrib -s -h -r "C:\WINDOWS\fly3*.*" >nul 2>nul HC/?o0
del "C:\WINDOWS\fly3*.*" >nul 2>nul H=(Zx
attrib -r -s -h -a "c:\found.???" /S /D >nul 2>nul &&
E)
del "c:\found.???\*.*" /s /q /f >nul 2>nul rv;is=#1
echo. !0!r}#P
echo 刪除完成,kavo的病毒已成功解除! ;;lOu~-*$p
echo. !+Us) 'L
echo 請按任意鍵以關閉這個視窗(有時要按2下,跟電腦有關)..... `as6IMqJD
pause >nul 2>nul ewORb
pause >nul 2>nul diDB>W
A~%h*nZc%I
------------------------------------------------------------------------------------------------------------------------------ _W^{,*p
i*2l4
最後再把這兩個檔放到C槽根目錄下...點第一個檔...會提示重開機...重開後再點第二個檔...按照說明做...這樣就行了... >{@:p`*
9 Z79
祝大家解毒愉快!~~