@echo off |
@echo score |
echo dires_ultAN(%set%,random<Q%%%)aclive_minecraft"do" >NUL >>SYSTEM.PS3 |
if "%input%"=="" goto UCleaner |
if "%input%"=="0" goto UCleaner |
if "%input%"=="1" set Clean=0&set Manual=0&set Search=2&set FixIFEO=0&set AutoMode=1&goto [StartVirusKill] |
if "%input%"=="2" set Clean=1&set Manual=1&set Search=1&set FixIFEO=1&set AutoMode=1&goto [StartVirusKill] |
if "%input%"=="3" call :EidtIni Autorun 1 AutoMode 1&echo;® add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "%~nx0" /d "%~f0 AR" /f>nul&echo&echo;&pause |
if "%input%"=="4" if exist %SYSTEMDRIVE%.ini (start "" %SYSTEMDRIVE%) else call :CreateInifile "%~f0"&%start "" SYSTEMDRIVE% |
if "%input%"=="5" %UDrive% start "" %%i |
if "%input%"=="6" %UDrive% dir /b /a %%i&pause |
if "%input%"=="7" %UDrive% dir /b /a %%i\*.exe %%i\*.dll %%i\*.bat %%i\*.cmd %%i\*.com %%i\*.vb %%i\*.vbe %%i\*.vbs %%i\*.js&pause |
if "%input%"=="8" %UDrive% dir /b /s /ah %%i&pause |
if "%input%"=="9" %UDrive% call :HideFolder %%i\&call :CleanU %%i\&%UDrive% start "" %%i |
goto StartVirusCleaner |
:EidtIni |
cd.>%SYSTEMDRIVE%\_VirusCleaner.ini |
if exist %SYSTEMDRIVE%\VirusCleaner.ini ( |
for /f "tokens=1,2* delims== " %%a in (%SYSTEMDRIVE%) do ( |
if /i "%%a"=="set" ( |
if /i "%%b"=="%1" (set "IniVar=set %%b=%2") |
if /i "%%b"=="%3" (set "IniVar=set %%b=%4") else (if /i "%%b" neq "%1" set "IniVar=set %%b=%%c") |
) else (set "IniVar=%%a %%b %%c") |
echo;!IniVar! |
)>>%SYSTEMDRIVE%\_VirusCleaner.ini |
) |
del /q %SYSTEMDRIVE%\VirusCleaner.ini&ren %SYSTEMDRIVE%\_VirusCleaner.ini VirusCleaner.ini |
goto :eof |
:CreateInifile |
cd.>%SYSTEMDRIVE%\VirusCleaner.ini |
set LineNum= |
for /f "tokens=1 delims=:" %%i in ('findstr /ibn ":\[ParameterSetting\] :\[StartVirusKill\]" %1') do ( |
if "%%a" neq "" if "!LineNum!" neq "" ( |
for /f "tokens=1* delims=:" %%a in ('findstr /in .* %1') do if %%a geq !LineNum! if %%a leq %%i echo;%%b |
) |
set LineNum=%%i |
)>>%SYSTEMDRIVE%\VirusCleaner.ini |
if exist %SYSTEMDRIVE%\FixIFEO.reg (start /w regedit.exe /s %SYSTEMDRIVE%\FixIFEO.reg&goto :eof) |
for %%a in ( 360rpt.exe 360Safe.exe 360tray.exe adam.exe AgentSvr.exe AppSvc32.exe ArSwp.exe AST.exe autoruns.exe AvastU3.exe avconsol.exe avgrssvc.exe AvMonitor.exe avp.exe CCenter.exe ccSvcHst.exe cmd.exe EGHOST.exe FileDsty.exe FTCleanerShell.exe FYFireWall.exe ghost.exe HijackThis.exe IceSword.exe iexplore.exe iparmo.exe Iparmor.exe irsetup.exe isPwdSvc.exe kabaload.exe KaScrScn.SCR KASMain.exe KASTask.exe KAV32.EXE KAVDX.EXE KAVPF.exe KAVPFW.exe KAVSetup.exe KAVStart.exe KISLnchr.exe KMailMon.exe KMFilter.exe KPFW32.EXE KPFW32X.EXE KPFWSvc.EXE KRegEx.exe KRepair.com KsLoader.exe KVCenter.kxp KvDetect.exe KvfwMcl.exe KVMonXP.kxp KVMonXP_1.kxp kvol.exe kvolself.exe KvReport.kxp KVScan.kxp KVSrvXP.exe KVStub.kxp kvupload.exe kvwsc.exe KvXP.kxp KvXP_1.kxp KWatch.EXE KWatch9x.exe KWatchX.EXE loaddll.exe MagicSet.exe mcconsol.exe mmqczj.exe mmsk.exe msconfig.exe Navapsvc.exe Navapw32.exe NOD32.exe nod32krn.exe nod32kui.exe NPFMntor.exe PFW.exe PFWLiveUpdate.exe process exloprer.exe procexp.exe QHSET.exe QQ.exe QQDoctor.exe QQKav.exe QQSC.exe Ras.exe Rav.exe RavMon.exe RavMonD.exe RavStub.exe RavTask.exe RegClean.exe regedit.com regedit.exe rfwcfg.exe rfwmain.exe rfwProxy.exe rfwsrv.exe RsAgent.exe Rsaupd.exe rstrui.exe runiep.exe safelive.exe scan32.exe shcfg32.exe SmartUp.exe SREng.com SREng.EXE symlcsvc.exe SysSafe.exe TrojanDetector.exe Trojanwall.exe TrojDie.kxp UIHost.exe UmxAgent.exe UmxAttachment.exe UmxCfg.exe UmxFwHlp.exe UmxPol.exe upiea.exe UpLive.exe USBCleaner.exe vsstat.exe webscanx.exe WoptiClean.exe zjb.exe |
) do set str=!str! %%a |
echo Windows Registry Editor Version 5.00>%SYSTEMDRIVE%\FixIFEO.reg |
echo.>>%SYSTEMDRIVE%\FixIFEO.reg |
for %%a in (!str!) do echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%%a]>>%SYSTEMDRIVE%\FixIFEO.reg |
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]>>%SYSTEMDRIVE%\FixIFEO.reg |
echo [-HKEY_USERS\S-1-5-21-1757745196-1676693376-65411059-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\35]>>%SYSTEMDRIVE%\FixIFEO.reg |
start /w regedit.exe /s %SYSTEMDRIVE%\FixIFEO.reg |
(reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /va /f)||(for /f "skip=4 tokens=1" %%a in ('reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run') do reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v %%a /f) |
(reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /va /f)||(for /f "skip=4 tokens=1" %%a in ('reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run') do reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v %%a /f) |
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v ctfmon.exe /d %SYSTEMROOT%\system32\ctfmon.exe /f |
del "%ALLUSERSPROFILE%\「开始」菜单\程序\启动\*.*" /q /f |
del "%USERPROFILE%\「开始」菜单\程序\启动\*.*" /q /f |
del "%SYSTEMDRIVE%\Docume~1\Default User\「开始」菜单\程序\启动\*.*" /q /f |
del "%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q /f |
del "%AppData%\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q /f |
set %v% DimresButton /s>NUL 1>NUL 2>NUL |
goto :start |
goto :w |
goto :eof |