这个附件是个批处理程序,经检查不存在恶意代码:
@echo off
::-----------------------------------------------
:: 没有小伞\瑞星双击打不开\升级没有反应\升级蓝屏
::-----------------------------------------------
Title [2008]
@echo 程序运行后将计算机将自动重新启动
@echo 请您关闭现有程序
@echo 请按任意键继续运行
pause
::命令开始-----------------------------------
@echo off
if exist %HOMEDRIVE%\virusup del %HOMEDRIVE%\virusup /f /s /q
if not exist %HOMEDRIVE%\virusup md %HOMEDRIVE%\virusup
:delregfpids32
reg save HKLM\SYSTEM\CurrentControlSet\Services\fpids32 %HOMEDRIVE%\virusup\fpids32.hiv
reg delete HKLM\SYSTEM\CurrentControlSet\Services\fpids32 /F
reg save HKLM\SYSTEM\CurrentControlSet\Services\msfpfis64 %HOMEDRIVE%\virusup\msfpfis64.hiv
reg delete HKLM\SYSTEM\CurrentControlSet\Services\msfpfis64 /F
reg save HKLM\SYSTEM\CurrentControlSet\Services\msert %HOMEDRIVE%\virusup\msert.hiv
reg delete HKLM\SYSTEM\CurrentControlSet\Services\msert /F
reg save HKLM\SYSTEM\CurrentControlSet\Services\RemoteStorage %HOMEDRIVE%\virusup\RemoteStorage.hiv
reg delete HKLM\SYSTEM\CurrentControlSet\Services\RemoteStorage /F
reg export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run %HOMEDRIVE%\virusup\run.reg
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /F
reg save HKCU\SYSTEM\CurrentControlSet\Services %HOMEDRIVE%\virusup\cuser.hiv
reg delete HKCU\SYSTEM\CurrentControlSet\Services /F
reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" %HOMEDRIVE%\virusup\iebho.reg
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" /F
reg export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run %HOMEDRIVE%\virusup\EXRUN.reg
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run /F
:delfiles
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\drivers\msosfpids32.sys
MOVE /Y %SYSTEMROOT%\system32\drivers\msosfpids32.sys %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\drivers\msosfpids32.sys
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\drivers\msosmsfpfis64.sys
MOVE /Y %SYSTEMROOT%\system32\drivers\msosmsfpfis64.sys %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\drivers\msosmsfpfis64.sys
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\drivers\MSELK.SYS
MOVE /Y %SYSTEMROOT%\system32\drivers\MSELK.SYS %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\drivers\MSELK.SYS
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\WINNET.EXE
MOVE /Y %SYSTEMROOT%\system32\drivers\WINNET.EXE %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\drivers\WINNET.EXE
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\msosmhfp00.dll
MOVE /Y %SYSTEMROOT%\system32\msosmhfp00.dll %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\msosmhfp00.dll
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\msosmhfp01.dll
MOVE /Y %SYSTEMROOT%\system32\msosmhfp01.dll %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\msosmhfp01.dll
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\msosiocp.dll
MOVE /Y %SYSTEMROOT%\system32\msosiocp.dll %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\msosiocp.dll
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\IJOUGIEMNAW.DLL
MOVE /Y %SYSTEMROOT%\system32\IJOUGIEMNAW.DLL %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\IJOUGIEMNAW.DLL
ATTRIB -s -h -r -a %SYSTEMROOT%\system32\setup\en_1072.bin
MOVE /Y %SYSTEMROOT%\system32\setup\en_1072.bin %HOMEDRIVE%\virusup
md %SYSTEMROOT%\system32\setup\en_1072.bin
ATTRIB -s -h -r -a %SYSTEMROOT%\SYSTEM32\INTERNE.EXE
MOVE /Y %%SYSTEMROOT%\SYSTEM32\INTERNE.EXE %HOMEDRIVE%\virusup
md %SYSTEMROOT%\SYSTEM32\INTERNE.EXE
ATTRIB -s -h -r -a %SYSTEMROOT%\DbgHlp32.exe
MOVE /Y %%SYSTEMROOT%\DbgHlp32.exe %HOMEDRIVE%\virusup
md %SYSTEMROOT%\DbgHlp32.exe
ATTRIB -s -h -r -a %SYSTEMROOT%\upxdnd.exe
MOVE /Y %%SYSTEMROOT%\upxdnd.exe %HOMEDRIVE%\virusup
md %SYSTEMROOT%\upxdnd.exe
ATTRIB -s -h -r -a %SYSTEMROOT%\AVPSrv.exE
MOVE /Y %%SYSTEMROOT%\AVPSrv.exE %HOMEDRIVE%\virusup
md %SYSTEMROOT%\AVPSrv.exE
ATTRIB -s -h -r -a %SYSTEMROOT%\cmdbcs.exe
MOVE /Y %%SYSTEMROOT%\cmdbcs.exe %HOMEDRIVE%\virusup
md %SYSTEMROOT%\cmdbcs.exe
ATTRIB -s -h -r -a %temp%\tmp*.tmp
MOVE /Y %temp%\tep*.tmp %HOMEDRIVE%\virusup
ATTRIB -s -h -r -a %temp%\*.sys
MOVE /Y %temp%\*.sys %HOMEDRIVE%\virusup
ATTRIB -s -h -r -a "%HOMEDRIVE%\Program Files\Internet Explorer\IEXPLORE32.*"
MOVE /Y "%HOMEDRIVE%\Program Files\Internet Explorer\IEXPLORE32.*" %HOMEDRIVE%\virusup
:ifabat
if exist %HOMEDRIVE%\temp\a.bat del %HOMEDRIVE%\temp\a.bat /f /q
if exist %HOMEDRIVE%\temp\b.bat del %HOMEDRIVE%\temp\b.bat /f /q
:rspcaddreg
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v virustrj /d %systemroot%\temp\a.bat
for /f "skip=4 tokens=2 delims=:" %%i in ('reg query "HKLM\SOFTWARE\rising\rav" /v installpath') do set temp1=%%~pi
for /f "skip=4 tokens=1 delims=\" %%j in ('reg query "HKLM\SOFTWARE\rising\rav" /v installpath') do set temp2=%%j
for /f "tokens=3" %%k in ('echo %temp2%') do set temp3=%%k
set a=%temp3%%temp1%
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v ravrstp /d "%a%rav\Update\Setup.exe -repair"
:addabat
echo echo off >>%systemroot%\temp\a.bat
echo reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /v virustrj /d %systemroot%\temp\b.bat>>%systemroot%\temp\a.bat
echo reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /D "" /f >>%systemroot%\temp\a.bat
echo reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /F >>%systemroot%\temp\a.bat
echo reg ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path" /v Debugger /t REG_SZ /D "ntsd -d" /F >>%systemroot%\temp\a.bat
echo reg ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path" /v GlobaFlag /t REG_SZ /D "0x000010F0" /F>>%systemroot%\temp\a.bat
:addbbat
echo reg import %HOMEDRIVE%\virusup\run.reg >>%systemroot%\temp\b.bat
echo reg import %HOMEDRIVE%\virusup\iebho.reg >>%systemroot%\temp\b.bat
echo reg import %HOMEDRIVE%\virusup\EXRUN.reg >>%systemroot%\temp\b.bat
:end
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /F
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /V {50632D5C-B71B-4ba0-B012-3DC6F15C011B} /F
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /V {7FA4A83B-F99A-4bfc-A8E2-6A62B05D2C82} /F
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /V WinShell /F
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /f
shutdown -r -f -t 00
pause
::命令结束-----------------------------------