<!DOCTYPEHTMLPUBLIC"-//W3C//DTDXHTML1.0Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<htmlxmlns="http://www.w3.org/1999/xhtml">
<head>
<title>七位字母命名的病毒专杀工具</title>
<HTA:APPLICATION
APPLICATIONNAME="KILLVIRUS"
border="thin"
borderstyle="normal"
caption="yes"
icon="c.ico"
maximizebutton="no"
minimizebutton="yes"
showintaskbar="yes"
singleinstance="yes"
sysmenu="yes"
version="1.0"
windowState="normal"
>
<styletype="text/css">
body{background-color:#FFF}
body,input{font:9pttahoma}
bodya{font-size:12px;text-decoration:none}
bodya:link{color:#0000CC;text-decoration:none}
bodya:visited{color:#0000CC;text-decoration:none}
fieldset{height:230x}
legend{font-weight:bolder}
#DataArea{color:#FF0000}
textarea{scrollbar-face-color:#FFF;
scrollbar-arrow-color:#000;
scrollbar-base-color:#FFF;
scrollbar-dark-shadow-color:##2D5B2D;
}
</style>
</head>
<scriptlanguage="VBScript">
SubWindow_onLoad
window.resizeTo620,400
EndSub
SubDONOW
DataArea.InnerHTML="正在进行快速杀毒……请稍等……"
EndSub
SubDOEND
DataArea.InnerHTML="病毒清除成功,如果你发现有本专杀不能清除的病毒,请提交样本:ycosxhack@126.com,压缩加密virus。"
EndSub
SubKILLVIRUS
DONOW
onerrorresumenext
msgbox"本专杀由余弦函数制作,点击确实开始杀毒。",64,"Autorun随机七位字母命名的病毒专杀"
setw=getobject("winmgmts:")
setp=w.execquery("select*fromwin32_processwherename='dmecvcm.exe'orname='iywdqdf.exe'orname='oduxyym.exe'orname='wojhadp.exe'orname='rmwaccq.exe'orname='dtstorp.exe'orname='ouvjwsc.exe'orname='wocfiba.exe'orname='gnkjkrl.exe'orname='lnmwiid.exe'orname='suvtufx.exe'orname='wojhadp.exe'orname='rmwaccq.exe'orname='egclmvo.exe'orname='cyqttve.exe'")
foreachiinp
i.terminate
next
setfso=createobject("scripting.filesystemobject")
setdel=createobject("wscript.shell")
dimd(16)
dimv(16)
d(0)=del.ExpandEnvironmentStrings("%SystemRoot%system32dmecvcm.exe")
d(1)=del.ExpandEnvironmentStrings("%SystemRoot%system32iywdqdf.exe")
d(2)=del.ExpandEnvironmentStrings("%SystemRoot%system32meex.com")
d(3)=del.ExpandEnvironmentStrings("%SystemRoot%system32oduxyym.exe")
d(4)=del.ExpandEnvironmentStrings("%SystemRoot%system32wojhadp.exe")
d(5)=del.ExpandEnvironmentStrings("%SystemRoot%system32rmwaccq.exe")
d(6)=del.ExpandEnvironmentStrings("%SystemRoot%system32dtstorp.exe")
d(7)=del.ExpandEnvironmentStrings("%SystemRoot%system32ouvjwsc.exe")
d(8)=del.ExpandEnvironmentStrings("%SystemRoot%system32wocfiba.exe")
d(9)=del.ExpandEnvironmentStrings("%SystemRoot%system32gnkjkrl.exe")
d(10)=del.ExpandEnvironmentStrings("%SystemRoot%system32lnmwiid.exe")
d(11)=del.ExpandEnvironmentStrings("%SystemRoot%system32suvtufx.exe")
d(12)=del.ExpandEnvironmentStrings("%SystemRoot%system32wojhadp.exe")
d(13)=del.ExpandEnvironmentStrings("%SystemRoot%system32rmwaccq.exe")
d(14)=del.ExpandEnvironmentStrings("%SystemRoot%system32egclmvo.exe")
d(15)=del.ExpandEnvironmentStrings("%SystemRoot%system32cyqttve.exe")
fori=0to15
setv(i)=fso.getfile(d(i))
v(i).attributes=0
v(i).delete
next
setfso=createobject("scripting.filesystemobject")
setdrvs=fso.drives
foreachdrvindrvs
ifdrv.drivetype=1ordrv.drivetype=2ordrv.drivetype=3ordrv.drivetype=4then
setw=fso.getfile(drv.driveletter&":kocmbcd.exe")
w.attributes=0
w.delete
setw_1=fso.getfile(drv.driveletter&":vlskjgs.exe")
w_1.attributes=0
w_1.delete
setw_2=fso.getfile(drv.driveletter&":haqeyfy.exe")
w_2.attributes=0
w_2.delete
setw_3=fso.getfile(drv.driveletter&":udnnnvq.exe")
w_3.attributes=0
w_3.delete
setw_3=fso.getfile(drv.driveletter&":nqgphqd.exe")
w_3.attributes=0
w_3.delete
setw_4=fso.getfile(drv.driveletter&":cmxpbpl.exe")
w_4.attributes=0
w_4.delete
setu=fso.getfile(drv.driveletter&":autorun.inf")
u.attributes=0
u.delete
endif
next
setreg=createobject("wscript.shell")
reg.regwrite"HKLMSYSTEMCurrentControlSetServicesAVPStart",2,"REG_DWORD"
reg.regwrite"HKLMSYSTEMCurrentControlSetServicesSharedAccessStart",2,"REG_DWORD"
reg.regwrite"HKLMSYSTEMCurrentControlSetServiceshelpsvcStart",2,"REG_DWORD"
reg.regwrite"HKLMSYSTEMCurrentControlSetServiceswuauservStart",2,"REG_DWORD"
reg.regwrite"HKLMSYSTEMCurrentControlSetServiceswscsvcStart",2,"REG_DWORD"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenSHOWALLCheckedValue",1,"REG_DWORD"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenSHOWALLDefaultValue",2,"REG_DWORD"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenNOHIDDENCheckedValue",2,"REG_DWORD"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenNOHIDDENDefaultValue",2,"REG_DWORD"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenUncheckedValue",1,"REG_DWORD"
reg.regdelete"HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunhhsonxn"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunkocmbcd"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunhaqeyfy"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunvlskjgs"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunudnnnvq"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunuragvod"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRuncfrxjwg"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunnqgphqd"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRuncmxpbpl"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsCurrentVersionRundnpsalq"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRas.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsavp.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsruniep.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsPFW.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsFYFireWall.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsrfwmain.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsrfwsrv.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAVPF.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKPFW32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsnod32kui.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsnod32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsNavapsvc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsNavapw32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsavconsol.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionswebscanx.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsNPFMntor.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsvsstat.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKPfwSvc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRavTask.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRav.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRavMon.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsmmsk.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsWoptiClean.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsQQKav.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsQQDoctor.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsEGHOST.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptions360Safe.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsiparmo.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsadam.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsIceSword.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptions360rpt.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptions360tray.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsAgentSvr.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsAppSvc32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsautoruns.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsavgrssvc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsAvMonitor.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsCCenter.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsccSvcHst.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsFileDsty.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsFTCleanerShell.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsHijackThis.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsIparmor.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsisPwdSvc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskabaload.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKASMain.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKASTask.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAV32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAVDX.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAVPFW.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAVSetup.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKAVStart.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKISLnchr.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKMailMon.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKMFilter.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKPFW32X.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKRegEx.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKsLoader.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKvDetect.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKvfwMcl.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskvol.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskvolself.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVSrvXP.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskvupload.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskvwsc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKWatch.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKWatch9x.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKWatchX.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsloaddll.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsMagicSet.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsmcconsol.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsmmqczj.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsnod32krn.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsPFWLiveUpdate.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsQHSET.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRavMonD.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRavStub.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRegClean.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsrfwcfg.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRsAgent.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsRsaupd.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionssafelive.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsscan32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsshcfg32.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsSmartUp.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsSREng.EXE"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionssymlcsvc.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsSysSafe.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsTrojanDetector.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsTrojanwall.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUIHost.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUmxAgent.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUmxAttachment.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUmxCfg.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUmxFwHlp.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUmxPol.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsUpLive.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsupiea.exe"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsavp.com"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKaScrScn.SCR"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKRepair.com"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVCenter.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVMonXP.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVMonXP_1.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKvReport.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVScan.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKVStub.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKvXP.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsKvXP_1.kxp"
reg.regdelete"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsTrojDie.kxp"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsdmecvcm.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsiywdqdf.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsmeex.comDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsoduxyym.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionswojhadp.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsrmwaccq.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsdtstorp.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsouvjwsc.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionswocfiba.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsgnkjkrl.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionslnmwiid.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionssuvtufx.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionswojhadp.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsrmwaccq.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionskocmbcd.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsvlskjgs.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionshaqeyfy.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsudnnnvq.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsnqgphqd.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionsegclmvo.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionscyqttve.exeDebugger","NoVirus","REG_SZ"
reg.regwrite"HKLMSOFTWAREMicrosoftWindowsNTCurrentVersionImageFileExecutionOptionscmxpbpl.exeDebugger","NoVirus","REG_SZ"
setfso=nothing
DOEND
EndSub
SubEXITKILL
window.close()
EndSub
</script>
<body>
<inputtype="button"value="KillVirus"onClick="KILLVIRUS">
<inputtype="button"value="MyBLOG"onClick="window.open('http://hi.baidu.com/ycosxhack')">
<inputtype="button"value="EXIT"onClick="EXITKILL">
<-------------------------专杀更新时间2007年6月7日POWEREDBY<ahref="http://hi.baidu.com/ycosxhack">余弦函数</a>
<p><spanid=DataArea>点击KillVirus开始杀毒……</span><p>
<fieldset>
<legend>-ReadMeFirst-</legend>
<textareaid="readme"style="border:0;background-color:#FFFFFF;width:98%;height:226px;">
Autorun随机七位字母命名的病毒专杀
1、专杀目前可以完全查杀kocmbcd.exe、ouvjwsc.exen、qgphqd.exe、udnnnvq.exe与cmxpbpl.exe通过移动盘传播的病毒!这些都是同类病毒的变种,遇到新变种我会继续更新杀毒指令。
2、如果你中的是其它变种的Virus.Win32.AutoRun或Trojan-Downloader.Win32.Agent,运行此专杀将能暂时解决部分问题。你可以将病毒样本发到此邮箱ycosxhack@126.com,以便我更新杀毒指令。
3、转载本专杀的源码请务必保持源码的完整性……
BY余弦函数2007年6月7日http://hi.baidu.com/ycosxhack<--我的博客
</textarea>
</fieldset>
</body>
</html>
打包文件下载