您的位置首页生活小窍门

跪求global.exe的删除方法

跪求global.exe的删除方法

把下面的内容复制到记事本扩展名改成bat然后运行即可!@echo off title 金来全 Global.exe删除代码 color 0a taskkill /im Global.exe /t /f taskkill /im tskmgr.exe /t /fattrib -s -h -r c:\autorun.inf attrib -s -h -r C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.comattrib -s -h -r C:\WINDOWS\pchealth\Global.exe attrib -s -h -r C:\WINDOWS\system32\dllcache\Default.exe attrib -s -h -r C:\WINDOWS\pchealth\Global.exeattrib -s -h -r C:\WINDOWS\system\KEYBOARD.exeattrib -s -h -r C:\WINDOWS\Fonts\Fonts.exeattrib -r -s -h C:\MS-DOS.comattrib -r -s -h C:\WINDOWS\Cursors\Boom.vbsattrib -r -s -h C:\windows\fonts\tskmgr.exeattrib -r -s -h C:\windows\system32\dllcache\recycler.{645ff040-5081-101b-9f08-00aa002f954e}\global.exeattrib -r -s -h C:\洞袭嫌windows\禅滚system32\dllcache\rndll32.exeattrib -r -s -h C:\windows\system32\drivers\drivers.cab.exedel c:\autorun.inf del C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.comdel C:\WINDOWS\pchealth\纳手Global.exedel C:\WINDOWS\system32\dllcache\Default.exe del C:\WINDOWS\pchealth\Global.exedel C:\windows\fonts\tskmgr.exedel C:\WINDOWS\system\KEYBOARD.exedel C:\WINDOWS\Fonts\Fonts.exedel C:\MS-DOS.comdel C:\WINDOWS\Cursors\Boom.vbsdel C:\windows\system32\dllcache\recycler.{645ff040-5081-101b-9f08-00aa002f954e}\global.exedel C:\windows\system32\dllcache\rndll32.exedel C:\windows\system32\drivers\drivers.cab.exefor /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\autorun.inf attrib -s -h -r %%d:\autorun.inf for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\autorun.inf del %%d:\autorun.inf /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com attrib -s -h -r %%d:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\pchealth\Global.exe attrib -s -h -r %%d:\WINDOWS\pchealth\Global.exefor /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\system32\dllcache\Default.exe attrib -s -h -r %%d:\WINDOWS\system32\dllcache\Default.exe for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\system\KEYBOARD.exe attrib -s -h -r %%d:\WINDOWS\system\KEYBOARD.exefor /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\Fonts\Fonts.exe attrib -s -h -r %%d:\WINDOWS\Fonts\Fonts.exefor /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\MS-DOS.com attrib -s -h -r %%d:\MS-DOS.comfor /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com del %%d:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\pchealth\Global.exe del %%d:\WINDOWS\pchealth\Global.exe /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\system32\dllcache\Default.exe del %%d:\WINDOWS\system32\dllcache\Default.exe /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\system\KEYBOARD.exe del %%d:\WINDOWS\system\KEYBOARD.exe /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\WINDOWS\Fonts\Fonts.exe del %%d:\WINDOWS\Fonts\Fonts.exe /q for /D %%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist %%d:\MS-DOS.com del %%d:\MS-DOS.com /q 'clsset rg = createobject("wscript.shell")on error resume nextrg.regwrite "HKCR\.vbs\", "VBSFile"rg.regwrite "HKCU\Control Panel\Desktop\SCRNSAVE.EXE", ""rg.regwrite "HKCU\Control Panel\Desktop\ScreenSaveTimeOut", "30"rg.regwrite "HKCR\MSCFile\Shell\Open\Command\", ""rg.regwrite "HKCR\regfile\Shell\Open\Command\", ""rg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\", ""rg.regwrite "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\", ""rg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\", ""rg.regwrite "HKEY_CLASSES_ROOT\MSCFile\Shell\Open\Command\", ""rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\DisplayName","Local Group Policy"rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\FileSysPath",""rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\GPO-ID","LocalGPO"rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\GPOName","Local Group Policy" rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\SOM-ID","Local" rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\0\Parameters",""rg.regwrite "HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\0\0\Script",""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\DisplayName", "Local Group Policy"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\FileSysPath", ""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\GPO-ID", "LocalGPO"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\GPOName", "Local Group Policy"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\SOM-ID", "Local"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\0\Parameters", ""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\0\Script", ""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\DisplayName", "Local Group Policy"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\FileSysPath", ""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\GPO-ID", "LocalGPO"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\GPOName", "Local Group Policy"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\SOM-ID", "Local"rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\0\Parameters", ""rg.regwrite "HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\0\Script", ""clsset /p tmp=C盘该病毒清除完毕,请按回车开始删除其他分区病毒。 cls @echo off title 金来全 Global.bat删除代码 color 0a echo ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ echo. echo 例如:D盘无法打开则输入 d,你也可以输入d,e,f这样来同时 echo 对这三个分区操作。 echo. echo ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ set /p input=[请输入无法打开的分区的盘符] attrib -s -h -r %input%:\autorun.inf attrib -s -h -r %input%:\MS-DOS.comcls del %input%:\autorun.inf /q del %input%:\MS-DOS.com /q cls echo 操作成功结束,请重启,然后就可以双击就可以打开了。 echo 如果重启之后,还是无法双击打开的话,说明你的电脑 echo 里还有病毒,请先杀毒。然后再运行该程序。 set /p tmp=操作结束,按回车键退出该程序。然后 http://zhaodx1.googlepages.com/XP_ctfmon_patch.rar下载后安装就行了注意给系统打补丁。祝你们好运~