其实全部也只是同一个文件改了后缀而已..都是同样的应用程序
不过不知道它还修改了我哪里...全部程序都运行不了....奇怪....
好在我本来已经准备重装
下面是杀这个病毒的bat....
还有问下.除了修改注册表 root 下的 exefile 关联外,还有哪里能够修改exe关联的??
倒,不让上传rar?????
attrib -a -h -r -s %windir%\1.com
attrib -a -h -r -s %windir%\ExERoute.exe
attrib -a -h -r -s %windir%\explorer.com
attrib -a -h -r -s %windir%\finder.com
attrib -a -h -r -s %windir%\WINLOGON.EXE
attrib -a -h -r -s %windir%\debug\DebugProgram.exe
attrib -a -h -r -s %windir%\system32\command.pif
attrib -a -h -r -s %windir%\system32\dxdiag.com
attrib -a -h -r -s %windir%\system32\finder.com
attrib -a -h -r -s %windir%\system32\MSCONFIG.COM
attrib -a -h -r -s %windir%\system32\regedit.com
attrib -a -h -r -s %windir%\system32\rundll32.com
attrib -a -h -r -s "C:\Program Files\Common Files\iexplore.pif"
attrib -a -h -r -s "C:\Program Files\Internet Explorer\iexplore.com"
del d:\pagefile.pif
del %windir%\1.com
del %windir%\ExERoute.exe
del %windir%\explorer.com
del %windir%\finder.com
del %windir%\WINLOGON.EXE
del %windir%\debug\DebugProgram.exe
del %windir%\system32\command.pif
del %windir%\system32\dxdiag.com
del %windir%\system32\finder.com
del %windir%\system32\MSCONFIG.COM
del %windir%\system32\regedit.com
del %windir%\system32\rundll32.com
del "C:\Program Files\Common Files\iexplore.pif"
del "C:\Program Files\Internet Explorer\iexplore.com"
del d:\autorun.inf
echo Windows Registry Editor Version 5.00>123.reg
echo. >>123.reg
echo [HKEY_CLASSES_ROOT\htmlfile\shell\opennew\command]>>123.reg
echo @="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" %1">>123.reg
echo. >>123.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>123.reg
echo "Torjan Program"="">>123.reg
echo. >>123.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]>>123.reg
echo "Torjan Program"="">>123.reg
echo. >>123.reg
echo. >>123.reg
regedit /s 123.reg
del 123.reg