關(guān)于手動(dòng)刪除U盤(pán)文件夾病毒的解決方法
手動(dòng)刪除U盤(pán)文件夾病毒
最近好多電腦中了U盤(pán)病毒,把U盤(pán)上所有正常文件夾隱藏,然后用病毒自己的程序充當(dāng)文件夾,引起電腦運(yùn)行緩慢,不能用注冊(cè)表、任務(wù)管理器,感興趣的朋友可以嘗試一下這個(gè)批處理方法...
將以下內(nèi)容另存文.bat批處理文檔。運(yùn)行試一下!
@REM -------------------------------------------------------------------------------------------------
@ECHO OFF
@REM VIRUS MAIN PROGRAM FILE'S NAME IS "RUNOUCE.EXE"
ECHO KILLING VIRUS MAIN PROGRAM IN MEMORY...
SET VIRUSPROG=RUNOUCE.EXE
SET VIRUSFILE=%SYSTEMROOT%SYSTEM32\%VIRUSPROG%
TASKLIST | FIND /I "%VIRUSPROG%"
IF %ERRORLEVEL% GEQ 1 (GOTO NOVIRUS)
:FINDVIRUS
TASKKILL /F /IM "%VIRUSPROG%" /T
TASKLIST | FIND /I "%VIRUSPROG%"
IF %ERRORLEVEL% EQU 0 ( GOTO FINDVIRUS ) ELSE ( GOTO KILLEDVIRUS )
:KILLEDVIRUS
ECHO VIRUS IN MEMORY KILLED!
ECHO NOW DELETING THE VIRUS FILES:
GOTO DELETEFILE
:NOVIRUS
ECHO THERE'S NO VIRUS IN YOUR MACHINE!
GOTO END
:DELETEFILE
ECHO DELETING VIRUS MAIN PROGRAM FILE AND EMAILS CREATED BY VIRUS...
@REM DELETE MAIN VIRUS PROGRAM FILE
ATTRIB -R -S -H %VIRUSFILE%
DEL %VIRUSFILE%
@REM DELETE EMAIL FILE.
SET FILENAME=%PROGRAMFILES%COMMON FILESMICROSOFT SHAREDSTATIONERYREADME.EML
IF EXIST %FILENAME% DEL %FILENAME%
SET FILENAME=%PROGRAMFILES%COMMON FILESSYSTEMADOREADME.EML
IF EXIST %FILENAME% DEL %FILENAME%
SET FILENAME=%PROGRAMFILES%NETMEETINGREADME.EML
IF EXIST %FILENAME% DEL %FILENAME%
ECHO REPAIRE REGISTRY:
ECHO ENABLING SYSTEM TASK MANAGER...
REG DELETE HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciessystem /V DisableTaskMgr /F
ECHO ENABLING SYSTEM REGISTRY TOOLS...
REG DELETE HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciessystem /V DisableRegistryTools /F
ECHO DELETE VIRUS REGISTRY ...
REG DELETE HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun /V Runonce /F
ECHO "DONE!"
:END
PAUSE
注意:該批處理只刪除在系統(tǒng)盤(pán)WindowsSystem32下的.病毒主程序,和幾個(gè)附加的email,不能刪除優(yōu)盤(pán)上的病毒。
【手動(dòng)刪除U盤(pán)文件夾病毒的解決方法】相關(guān)文章:
U盤(pán)病毒的認(rèn)識(shí)及防范措施08-09
關(guān)于U盤(pán)病毒的介紹與預(yù)防措施05-10
u盤(pán)不顯示的解決方法參考03-28
加快U盤(pán)傳輸速度的解決方法01-29