Copy the following content to notepad, save it as pandakiller. bat, and double-click pandakiller. bat. This script not only clears the program, but also prevents the virus from creating its related programs again.
In addition, to take care of the vast majority of users, this script deletes htm, html, asp, aspx, jsp, and PHP files, this will not lead to the loss of web pages in your favorites (because it is only a shortcut), but will lead to the loss of web pages stored on your hard disk. If you have such information, we recommend that you back up the data before anti-virus. I shall not be liable for any legal or moral obligations !;)
Download the following two items before clearing them. They will recover the infected exe and rarfile on your hard disk. After clearing them, run Jinshan and Jiangmin killing immediately, you can simply say goodbye to the vast majority of versions of pandatv. In addition, if you can not clear, please send me your virus a minute, my mailbox zdtd_qd@163.com, I will be targeted to improve the script.
Kingsoft pandatv killing:
Http://down.www.kingsoft.com/db/download/othertools/DuBaTool_WhBoy.BAT
Jiang min pandatv killing:
Http://ec.jiangmin.com/test/PandaKiller.rar
Copy codeThe Code is as follows: cd \
Back up the data before virus removal to avoid loss of important data. & Pause
@ Echo off
Taskkill/f/im fuckjacks.exe
Taskkill/f/im sovh0st.exe
Taskkill/f/im rose.exe
Taskkill/f/im sxs.exe
Taskkill/f/im spoclsv.exe
Taskkill/f/im nvscv32.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im iexpl0re.exe
Taskkill/f/im ZAQ5.exe
Taskkill/f/im expl0rer.exe
Taskkill/f/im wuauclt.exe
Taskkill/f/im zaq2.exe
Taskkill/f/im zaq4.exe
Taskkill/f/im zaq10.exe
Taskkill/f/im zaq2.exe
Taskkill/f/im zaq4.exe
Taskkill/f/im zaq10.exe
Taskkill/f/im ZAQ5.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq3.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq9.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Taskkill/f/im zaq8.exe
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v "Synchronization Manager"/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v FuckJacks/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v wlzs/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v mhs2/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v load/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zts2/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v svohost/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v iexpl0re/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq5/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v wuauclt/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v wsvbs/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v synu/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v msccr/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v NOPNewHelp/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v wsvbs/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v synu/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v msccr/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v NOPNewHelp/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq2/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq4/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq5/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq10/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq3/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq8/f
Reg delete HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq9/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq4/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq5/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq10/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq3/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq8/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v zaq9/f
Reg delete HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run/v svcshare/f
Del/f/s/q/a % windir % \ system32 \ fuckjacks.exe
Md % windir % \ system \ fuckjacks.exe
Del/f/s/q/a % system % \ drivers \ spoclsv.exe
Md % system % \ drivers \ spoclsv.exe
Del/f/s/q/a c: \ iexpl0re. bat
Del/f/s/q/a % windir % \ uninstall \ rundl132.exe
Md % windir % \ uninstall \ rundl132.exe
Del/f/s/q/a c: \ iexpl0re .*
Del/f/s/q/a c: \ Program Files \ internet explorer \ plugins \ system64.sys
Del/f/s/q/a % windir % \ 525181m.bmp
Del/f/s/q/a % windir % \ 210531.bmp
Del c: \ docume ~ 1 \ admini ~ 1 \ locals ~ 1 \ temp \ *. exe/f/s/q/
Del c: \ docume ~ 1 \ admini ~ 1 \ locals ~ 1 \ temp \ *. bat/f/s/q/
Del c: \ docume ~ 1 \ admini ~ 1 \ locals ~ 1 \ temp \ *. cmd/f/s/q/
Del/f/s/q/a % system % \ sxs.exe
Md % system % \ sxs.exe
Del/f/s/q/a % system % \ sovhost.exe
Md % system % \ svhost.exe
Del/f/s/q/a c: \ nvscv32.exe
Attrib-a-s-r-h c: \ sxs.exe
Del c: \ sxs.exe/q/f
Attrib-a-s-r-h c: \ autorun. inf
Del c: \ autorun. inf/q/f
Md c: \ autorun. inf
Attrib-a-s-r-h d: \ sxs.exe
Del d: \ sxs.exe/q/f
Attrib-a-s-r-h d: \ autorun. inf
Del d: \ autorun. inf/q/f
Md d: \ autorun. inf
Attrib-a-s-r-h e: \ sxs.exe
Del e: \ sxs.exe/q/f
Attrib-a-s-r-h e: \ autorun. inf
Del e: \ autorun. inf/q/f
Md e: \ autorun. inf
Attrib-a-s-r-h f: \ sxs.exe
Del f: \ sxs.exe/q/f
Attrib-a-s-r-h f: \ autorun. inf
Del f: \ autorun. inf/q/f
Md f: \ autorun. inf
Attrib-a-s-r-h g: \ sxs.exe
Del g: \ sxs.exe/q/f
Attrib-a-s-r-h g: \ autorun. inf
Del g: \ autorun. inf/q/f
Md g: \ autorun. inf
Attrib-a-s-r-h: \ sxs.exe
Del h: \ sxs.exe/q/f
Attrib-a-s-r-h: \ autorun. inf
Del h: \ autorun. inf/q/f
Md h: \ autorun. inf
Attrib-a-s-r-h I: \ sxs.exe
Del I: \ sxs.exe/q/f
Attrib-a-s-r-h I: \ autorun. inf
Del I: \ autorun. inf/q/f
Md I: \ autorun. inf
Del/f/s/q/a c: \ zaq5.exe
Del/f/s/q/a c: \ expl0rer.exe
Del/f/s/q/a c: \ wuauclt.exe
Del/f/s/q/a % windir % \ wuauclt.exe
Md % windir % \ wuauclt.exe
Del/f/s/q/a % windir % \ bbyb.exe
Md % windir % \ bbyb.exe
Del/f/s/q/a % windir % \ bbybs.exe
Md % windir % \ bbybs.exe
Del/f/s/q/a % windir % \ bbyb. dll
Md % windir % \ bbyb. dll
Del/f/s/q/a % windir % \ ies. dll
Md % windir % \ ies. dll
Del/f/s/q/a c: \ zaq2.exe
Del/f/s/q/a c: \ zaq4.exe
Del/f/s/q/a c: \ zaq5.exe
Del/f/s/q/a c: \ zaq10.exe
Md % windir % \ zaq2.exe
Md % windir % \ zaq4.exe
Md % windir % \ zaq5.exe
Md % windir % \ zaq10.exe
Del/f/s/q/a % system % \ EXPL0RER. EXE
Md % system % \ expl0rer.exe
Del/f/s/q/a % system % \ System32.dll
Del/f/s/q/a % system % \ System64.dll
Del/f/s/q/a % system % \ aelupsvc32.dll
Md % system % \ aelupsvc32.dll
Del/f/s/q/a c: \ zaq3.exe
Del/f/s/q/a c: \ zaq8.exe
Del/f/s/q/a c: \ zaq9.exe
Del c: \ *. htm/f/s/q/
Del c: \ *. html/f/s/q/
Del c: \ *. asp/f/s/q/
Del c: \ *. php/f/s/q/
Del c: \ *. aspx/f/s/q/
Del c: \ *. jsp/f/s/q/
Del d: \ *. htm/f/s/q/
Del d: \ *. html/f/s/q/
Del d: \ *. asp/f/s/q/
Del d: \ *. php/f/s/q/
Del d: \ *. aspx/f/s/q/
Del d: \ *. jsp/f/s/q/
Del e: \ *. htm/f/s/q/
Del e: \ *. html/f/s/q/
Del e: \ *. asp/f/s/q/
Del e: \ *. php/f/s/q/
Del e: \ *. aspx/f/s/q/
Del e: \ *. jsp/f/s/q/
Del f: \ *. htm/f/s/q/
Del f: \ *. html/f/s/q/
Del f: \ *. asp/f/s/q/
Del f: \ *. php/f/s/q/
Del f: \ *. aspx/f/s/q/
Del f: \ *. jsp/f/s/q/
Del g: \ *. htm/f/s/q/
Del g: \ *. html/f/s/q/
Del g: \ *. asp/f/s/q/
Del g: \ *. php/f/s/q/
Del g: \ *. aspx/f/s/q/
Del g: \ *. jsp/f/s/q/
Del h: \ *. htm/f/s/q/
Del h: \ *. html/f/s/q/
Del h: \ *. asp/f/s/q/
Del h: \ *. php/f/s/q/
Del h: \ *. aspx/f/s/q/
Del h: \ *. jsp/f/s/q/
Del I: \ *. htm/f/s/q/
Del I: \ *. html/f/s/q/
Del I: \ *. asp/f/s/q/
Del I: \ *. php/f/s/q/
Del I: \ *. aspx/f/s/q/
Del I: \ *. jsp/f/s/q/
Del c: \ System Volume Information \ *. */f/s/q/
Del d: \ System Volume Information \ *. */f/s/q/
Del e: \ System Volume Information \ *. */f/s/q/
Del f: \ System Volume Information \ *. */f/s/q/
Del g: \ System Volume Information \ *. */f/s/q/
Del h: \ System Volume Information \ *. */f/s/q/
Del I: \ System Volume Information \ *. */f/s/q/
Echo completed anti-virus !~~ If you have any questions, please contact QQ77456852 :)
Pause
Supplemental keywords:
"Pandatv" virus prevention patch released specifically killing pandatv boys dead pandatv methods to prevent pandatv burning patch
How to Prevent pandatv from burning incense pandatv killing the zoo Kingsoft killing Rising Star killing the latest variant of pandatv?