系統知識網 系統知識 U盤中瞭recycler病毒怎麼辦?recycler病毒徹底清除方法

U盤中瞭recycler病毒怎麼辦?recycler病毒徹底清除方法

recycler在電腦中原來是回收站文件夾,在顯示隱藏之後可以看到,但是recycler同時也是一種病毒,可以在U盤、磁盤中任意復制,那麼如果U盤中瞭recycler病毒該怎麼辦呢?需要知道的是U盤中本身不會帶recycler文件夾,有這個。

recycler在電腦中原來是回收站文件夾,在顯示隱藏之後可以看到,但是recycler同時也是一種病毒,可以在U盤、磁盤中任意復制,那麼如果U盤中瞭recycler病毒該怎麼辦呢?需要知道的是U盤中本身不會帶recycler文件夾,有這個文件夾很有可能就是中毒瞭,下面一起來看看解決方法。

recycler病毒徹底清除方法:

解決方法一:制作BAT專殺工具

1、復制下面的代碼到記事本中
@echo off
taskkill /im explorer.exe /f
for /d %%i in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist "%%i:/RECYCLER" (
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\desktop.ini -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\desktop.ini
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\INFO2 -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\INFO2
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500 -s -h -r
rd /q/s %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500
attrib %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500\desktop.ini -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500\desktop.ini
attrib %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500\INFO2 -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500\INFO2
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe
attrib %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500 -s -h -r
rd /q/s %%i:\RECYCLER\S-1-5-21-1960408961-1450960922-682003330-500
attrib %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500\desktop.ini -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500\desktop.ini
attrib %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500\INFO2 -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500\INFO2
attrib %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe -s -h -r
@del /q/s/f %%i:\RECYCLER\S-1-5-21-151679604-1924401545-338918334-500\UcHelp.exe
attrib %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500 -s -h -r
rd /q/s %%i:\RECYCLER\S-1-5-21-2516078899-3036549676-3356972236-500
rd /q/s %%i:\RECYCLER
)
echo Windows Registry Editor Version 5.00>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] >>C:\seesaw.reg
echo "DisableRegistryTools"=dword:00000000 >>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] >>C:\seesaw.reg
echo "NoFolderOptions"=dword:00000000 >>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] >>C:\seesaw.reg
echo "DisableTaskMgr"=dword:00000000 >>C:\seesaw.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] >>C:\seesaw.reg
echo "CheckedValue"=dword:00000001 >>C:\seesaw.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt] >>C:\seesaw.reg
echo "UncheckedValue"=dword:00000000 >>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] >>C:\seesaw.reg
echo "@shell32.dll,-30500"="顯示所有文件和文件夾" >>C:\seesaw.reg
echo "@shell32.dll,-30501"="不顯示隱藏的文件和文件夾" >>C:\seesaw.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] >>C:\seesaw.reg
echo "Shell"="Explorer.exe" >>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] >>C:\seesaw.reg
echo "NoDriveAutoRun"=hex:ff,ff,ff,03 >>C:\seesaw.reg
echo "NoSetTaskbar"=dword:00000000 >>C:\seesaw.reg
echo "NoDriveTypeAutoRun"=dword:000000ff >>C:\seesaw.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] >>C:\seesaw.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] >>C:\seesaw.reg
echo "NoDriveTypeAutoRun"=dword:000000ff >>C:\seesaw.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] >>C:\seesaw.reg
@reg import C:\seesaw.reg
@del /q C:\seesaw.reg
start explorer.exe
echo 清理RECYCLER病毒文件完成!
@Pause 按任意鍵繼續……
exit

返回顶部