卡卡技术团队
- 帖子:25779
- 注册:
2007-01-14
- 来自:
|
发表于:
2009-02-07 16:05
|
短消息
资料
回复: 会看日记的来看下
原帖由 随缘92WJC 于 2009-2-7 16:02:00 发表 我测试时先安了一些流氓软件杀软全关,运行批处理,运行时间很长,结束后注册表、文件夹中也没有找到流氓软件的痕迹说明能删除恶意,但系统启动变慢,所以一般我都不用这个工具清理恶意的了。这个做为急救用,应该没问题的吧 个人认为工具已老,功能主要是对付3721、CNNIC等老流氓的。 下面是你那个批处理的全内容,自己看看就明白了: rem 砍掉一切流氓,让我们静待互联网的春天 ~_~ rem 各取所需,根据自己要求修改(有的人还觉得某个流氓好就留着*_*) rem 如果跳出选择框,选择全部卸载 rem 有些**需要在安全模式下才能卸载,有些不好卸载请看里面的帮助 rem 现在的流氓越来越超级,已经超过批处理的能力极限,只有借助一些别的软件,推荐使用http://ccollomb.free.fr/unlocker一起删除超级** rem 砍掉3721 kao 把好多的电脑弄惨了 if exist C:\PROGRA~1\3721\Assist\asbar.dll rundll32.exe C:\PROGRA~1\3721\Assist\asbar.dll,RunSettings -uninstall if exist %windir%\downlo~1\CnsMin.dll rundll32.exe %windir%\downlo~1\CnsMin.dll,RunSettings -uninstall if exist %windir%\downlo~1\CnsMin.dll rundll32.exe %windir%\downlo~1\CnsMin.dll,ControlPanel regsvr32 /u /s %windir%\downlo~1\CnsMin.dll regsvr32 /u /s C:\PROGRA~1\3721\Assist\asbar.dll regsvr32 /u /s C:\PROGRA~1\3721\helper.dll regsvr32 /u /s C:\PROGRA~1\YiSou\yisou.dll del /f /q c:\windows\system32\3warerun.exe del /f /q c:\windows\system32\3waresrv.exe del /f /q c:\windows\system32\drivers\3waredrv.sys del /f /q c:\windows\system32\drivers\3waregsm.sys del /f /q c:\windows\system32\drivers\3wDrv100.sys del /f /q c:\windows\system32\drivers\3wFlt100.sys reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\3waredrv /f reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\3waregsm /f reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\3waresrv /f reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\3wdrv100 /f reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\3wflt100 /f sc delete 3wareSrv ping -n 3 127.1>nul cls echo. echo. echo 3ware恶意程序完全删除成功!!! rem 砍掉yahoo猪手,把好多的电脑弄惨 regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll regsvr32 /u /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL rem 新版的 猪手 根本不能选择卸载,*** if exist C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll rundll32 C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll,UnInstall rem 彩信通 又一个超级的**产生了 rem 想办法删除 %windir%\system32\drivers\Albus.SYS 这个万恶不赦的文件,才能彻底清理这个门户 rem 推荐使用 DOS 启动电脑,找到C盘 这个万恶不赦的文件 删除 rem 或者使用 http://ccollomb.free.fr/unlocker 删除,删除后可能造成系统不稳定,重启电脑执行2个批处理,再重启 regsvr32 /u /s C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL if exist C:\PROGRA~1\MMSASS~1\mmsass~1.dll rundll32.exe C:\PROGRA~1\MMSASS~1\mmsass~1.dll,Uninstall if exist %windir%\System32\stdup.dll rundll32.exe %windir%\System32\stdup.dll,Uninstall regsvr32 /u /s %windir%\system32\stdup.dll regsvr32 /u /s %windir%\system32\STDSVER.DLL regsvr32 /u /s %windir%\system\stdup.dll regsvr32 /u /s %windir%\system\STDSVER.DLL del %windir%\system32\drivers\Albus.SYS /q /f del %windir%\system32\Albus.DAT /q /f del %windir%\system32\almms.dat /q /f del %windir%\system32\alsmt.exe /q /f del C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL /q /f rem internet explorer helper regsvr32 /u /s %windir%\fonts\msshapi.dll rem 划词 huaci 又是一个走上不归路的超级** rem 这个**需要重启电脑,再次执行两个批处理文件操作才能被删除 C:\PROGRA~1\HuaCi\huaci\mUin.exe C:\PROGRA~1\wsearch\mUnInstall.exe %windir%\system32\msibm\Uninstall.exe %windir%\system\msibm\Uninstall.exe del %windir%\system32\drivers\abhcop.sys /q /f del %windir%\system32\DRIVERS\hcalway.sys /q /f rem Baidu这个**,**越来越超级,Baid* 也不例外 ;rem需要安全模式,或者想办法删除 %windir%\system32\drivers\BDGuard.SYS 这个文件才能卸载这个** if exist C:\PROGRA~1\baidu\bar\BaiduBar.dll rundll32.exe C:\PROGRA~1\baidu\bar\BaiduBar.dll,Uninstall regsvr32 /u /s %windir%\DOWNLO~1\BDSrHook.dll regsvr32 /u /s %windir%\DOWNLO~1\BDHelper.dll regsvr32 /u /s %windir%\DOWNLO~1\BDPlugin.dll regsvr32 /u /s C:\PROGRA~1\Baidu\Bar\BaiduBar.dll regsvr32 /u /s "C:\Program Files\Common Files\Baidu\Disk Search\dsie.dll" if exist %windir%\DOWNLO~1\BDHelper.dll rundll32.exe %windir%\DOWNLO~1\BDHelper.dll,DllRemove del %windir%\system32\drivers\BDGuard.SYS /q /f del %windir%\system32\BDGuard.DAT /q /f del %windir%\system32\BDGuardS.DAT /q /f del C:\PROGRA~1\baidu\bar\BaiduBar.dll rem windirected 傲迅 wmpdrm.dll rem 这个**卸载需在安全模式下进行,或终止explorer.exe,taskmgr.exe,输入法等进程只留基本进程,在CMD窗口中执行批处理可卸载 %windir%\system32\spoolsv\spoolsv.exe -uninst regsvr32 /u /s %windir%\system32\wmpdrm.dll del %windir%\system32\spoolsv\spoolsv.exe /q /f rem 为了98 %windir%\system\spoolsv\spoolsv.exe -uninst regsvr32 /u /s %windir%\system\wmpdrm.dll del %windir%\system\spoolsv\spoolsv.exe /q /f rem 删除QQ搜索 这个 ** regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\IEHelp.dll regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\IEHelp1.dll regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\scrax.dll regsvr32 /u /s C:\PROGRA~1\TENCENT\AddrPlus\TCtrl.dll C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\SSAddr1.dll Uninstall C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\SSAddr.dll Uninstall rem 删除 DUDU 搜索条 这个 ** regsvr32 /u /s C:\PROGRA~1\DuDu\DddClient\dddiemon.dll regsvr32 /u /s C:\PROGRA~1\DuDu\DddClient\dddmext.dll rem 删除Accoona 这个 ** regsvr32 /u /s C:\PROGRA~1\Accoona\AToolbarCN.dll regsvr32 /u /s C:\PROGRA~1\Accoona\atoolbar.dll regsvr32 /u /s C:\PROGRA~1\Accoona\ASearchAssist.dll rem 删除xBar regsvr32 /u /s C:\PROGRA~1\xBar\xBarHelper.dll regsvr32 /u /s %windir%\System32\xunleibho_v8.dll rem 为了98 regsvr32 /u /s %windir%\System\xunleibho_v8.dll rem Schedule sscli.dll regsvr32 /u /s %windir%\System32\sscli.dll rem 删除 henbang 很棒 ** regsvr32 /u /s C:\PROGRA~1\pcast\hbcast.dll regsvr32 /u /s C:\PROGRA~1\HBClient\hapast.dll regsvr32 /s /u C:\PROGRA~1\yehoo\hbyehoo.dll regsvr32 /s /u C:\PROGRA~1\yehoo\tbyehoo.dll regsvr32 /s /u %windir%\DOWNLO~1\HTHelper.dll rem 库站 多多QQ表情 9991.com51.com 超级** regsvr32 /u /s C:\PROGRA~1\CoolWebsite\QuickLink.dll "C:\Program Files\Common Files\update\update.exe" -kill1 C:\PROGRA~1\CoolWebsite\uninst.exe rem 最好安全模式操作,或者需要终止一个rundll32.exe %windir%\system32\wbem\IRJIT.dll 的进程 del %windir%\system32\wbem\IRJIT.dll /q /f rem cfsbho.dll regsvr32 /u /s %windir%\system32\msibm\cfsbho.dll rem 为了98 regsvr32 /u /s %windir%\system\msibm\cfsbho.dll rem 划词搜索 DeskAdTop\deskipn.dll regsvr32 /u /s C:\PROGRA~1\DESKAD~1\deskipn.dll C:\PROGRA~1\DESKAD~1\DeskUn.exe rem 删除桌面传媒 IE-BAR 这个** MsiExec.exe /I{FE41A479-E056-40A5-982C-D149B5D6712D} regsvr32 /u /s "C:\Program Files\Desktop Media\Cast\dmbar.dll" regsvr32 /u /s "C:\Program Files\Common Files\IE-Bar\dmbar.dll" "C:\Program Files\Common Files\IE-Bar\uninstall.exe" regsvr32 /u /s %windir%\DOWNLO~1\lund.dll regsvr32 /u /s "C:\Program Files\IE-BAR\Cast\dmbar.dll" rem 这个**可能不能被删除,请先到进程管理里删除VIPTray.exe这个进程 regsvr32 /u /s %windir%\system32\IEHelper.dll regsvr32 /u /s %windir%\system32\WinDefendor.dll rem 这个名字会不停的变化 ** regsvr32 /u /s %windir%\system\cb7o2470.dll rem 为了98 regsvr32 /u /s %windir%\system\IEHelper.dll regsvr32 /u /s %windir%\system\WinDefendor.dll MsiExec.exe /I{3D554C17-ED16-448A-B3CE-6FBC51FFB705} rem 中搜寻址 这个 ** regsvr32 /u /s "C:\Program Files\SearchNet\SNHpr.dll" "C:\Program Files\SearchNet\UnInstall.exe" rem 百狗** C:\PROGRA~1\baigoo\mtsrv.exe -UnregServer regsvr32 /u /s C:\PROGRA~1\baigoo\bgook.dll regsvr32 /u /s C:\PROGRA~1\baigoo\bgooex.dll regsvr32 /u /s C:\PROGRA~1\baigoo\BGooHK.dll regsvr32 /u /s C:\PROGRA~1\baigoo\BGooBHO.dll C:\PROGRA~1\baigoo\uninst.exe rem 搜狗 C:\PROGRA~1\P4P\Uninstall.exe regsvr32 /u /s "C:\Program Files\ScanToolbar\ScanBar.dll" C:\PROGRA~1\ScanToolbar\uninst.exe %windir%\system32\unsocul.exe rem 为了98 %windir%\system\unsocul.exe rem 点点通 if exist %windir%\DOWNLO~1\DDTINIT.DLL rundll32.exe %windir%\DOWNLO~1\DDTINIT.DLL,Uninstall rem Radiate Advertising %windir%\system32\MSIPCSV.EXE -uninstall -all rem 为了98 %windir%\system\MSIPCSV.EXE -uninstall -all rem RoomSetUPcd ads if exist %windir%\system32\cd_clint.dll rundll32 %windir%\system32\cd_clint.dll,ServiceRunDll u_281 rem 为了98 if exist %windir%\system\cd_clint.dll rundll32 %windir%\system\cd_clint.dll,ServiceRunDll u_281 rem 一个什么五笔 regsvr32 /u /s C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll rem wmicsmgr.dll regsvr32 /u /s %windir%\system32\wmicsmgr.dll regsvr32 /u /s %windir%\system\wmicsmgr.dll rem 一个广告Navihelper.dll regsvr32 /u /s %windir%\system32\Navihelper.dll regsvr32 /u /s %windir%\system\Navihelper.dll del %windir%\system32\host.dat /q /f rem 好像是一个木马 regsvr32 /u /s %windir%\system32\RAdminl.dll rem 为了98 regsvr32 /u /s %windir%\system\RAdminl.dll rem 跳跳塘 rem 这个**可能不能被删除,请先到进程管理里终止webacc.exe这个进程 %windir%\system32\wbauninstall.exe regsvr32 /u /s %windir%\system32\webacc.dll regsvr32 /u /s %windir%\Downlo~1\c8s.dll rem 为了98 %windir%\system\wbauninstall.exe regsvr32 /u /s %windir%\system\webacc.dll rem 好像什么便民 regsvr32 /u /s C:\PROGRA~1\xm\tbu3\xm.dll rem 易趣购物 del %windir%\ebaylink.ico /q /f rem msdc32.dll 一个木马 需要安全模式才能清除 del C:\PROGRA~1\COMMON~1\system\msdc32.dll /q /f del %windir%\ .exe /q /f /as /ar /ah rem YOK拦截助手 regsvr32 /u /s C:\PROGRA~1\YOK.com\BlockAdr\yokhad.dll regsvr32 /u /s C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll regsvr32 /u /s %windir%\system32\Navsmall.dll regsvr32 /u /s %windir%\system\Navsmall.dll C:\PROGRA~1\YOK.com\BlockAdr\Uninst.exe rem 不知是什么流氓 regsvr32 /u /s %windir%\DOWNLO~1\vevnli.dll rem ChajianHelper regsvr32 /u /s %windir%\system32\SYSREA~1.DLL regsvr32 /u /s %windir%\system\SYSREA~1.DLL rem 不知是什么流氓 regsvr32 /u /s %windir%\system32\HelperService.dll regsvr32 /u /s %windir%\system\HelperService.dll regsvr32 /u /s %windir%\system32\mshlp.dll regsvr32 /u /s %windir%\system\mshlp.dll rem MyWebSearch 这个**,这个**产生的目录根本不定 if exist rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsbar.dll rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsbar.dll,O rem 开心运程速递 regsvr32 /u /s %windir%\system32\obwbkya.dll rem 为了98 regsvr32 /u /s %windir%\system\obwbkya.dll regsvr32 /u /s %windir%\system32\shwasobj.dll rem 为了98 regsvr32 /u /s %windir%\system\shwasobj.dll C:\PROGRA~1\SDAstro\Uninst.exe rem 这个文件名会不停的变化 regsvr32 /u /s C:\Docume~1\AllUse~1\Applic~1\Microsoft\IEHelper\IEHelper200631_8913.dll rem Luobooshow regsvr32 /u /s %windir%\system32\WinSC.dll regsvr32 /u /s %windir%\system\WinSC.dll rem caishow regsvr32 /u /s "C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll" regsvr32 /u /s %windir%\system32\wuwebex.dll regsvr32 /u /s %windir%\system\wuwebex.dll rem 酷桌面 regsvr32 /u /s %windir%\system32\CoolBho.dll regsvr32 /u /s %windir%\system\CoolBho.dll rem 青娱 regsvr32 /u /s %windir%\system\QYLWMP~1.OCX regsvr32 /u /s %windir%\system\QYLRMP~1.OCX regsvr32 /u /s %windir%\system\contextmenu.dll regsvr32 /u /s C:\PROGRA~1\Qyule\\QYULEP~1.OCX regsvr32 /u /s C:\PROGRA~1\Qyule\\dvfilter.ax C:\PROGRA~1\Qyule\unins000.exe rem NB46.com smflash.ocx 好像需要安全模式 regsvr32 /u /s "C:\Program Files\nb46.com\NB46Toolbar.dll" regsvr32 /u /s %windir%\system32\smflash.ocx regsvr32 /u /s %windir%\system\smflash.ocx rem kuaiso toolsbar regsvr32 /u /s "C:\Program Files\Micrsoft SearchBar\SearchBar.dll" rem bbmao regsvr32 /u /s "C:\Program Files\bbmao Toolbar\bbmao_tb_v1_0.dll" rem 删除CDN 这个 ** regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\iesrch.dll regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll regsvr32 /u /s C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll regsvr32 /u /s %windir%\system32\cdnns.dll regsvr32 /u /s %windir%\System32\jklpif.dll rem 为了98 regsvr32 /u /s %windir%\system\cdnns.dll regsvr32 /u /s %windir%\System\jklpif.dll rem CNNIC的反安装这里可能不好完全卸载,请单独到控制面板里"添加/删除"里卸载,或找到C:\PROGRA~1\CNNIC\Cdn\cdnunins.exe单独执行 C:\PROGRA~1\CNNIC\Cdn\cdnunins.exe
超级游戏迷 最后编辑于 2009-02-07 16:08:11
打酱油的……
|