The latest virus SxS virus special kill way, recently hung horse serious _ virus killing

Source: Internet
Author: User
[%repeat_0 match= "/data/option"%] [%= @title%] [%= @count%] ticket [[%= @percent%]%]
[%_repeat_0%]


SXS. EXE this is a theft of QQ account password Trojan virus, the characteristics can be transmitted through removable disk. The virus's main harm is to steal QQ account and password, the virus will also end a large number of anti-virus software, reduce the security level of the system.
Poisoning symptom: Computer partition Double click cannot open automatically or hard to open, use right key to open can! This is the most obvious symptom!
Solution: Online has a lot of manual removal of the way!
Now there's the easiest way to do it, as follows:
1. Save the following red code as a *.bat file

@echo off
Attrib-s-h-r%windir%\system32\autorun.bat
Attrib-s-h-r%windir%\system32\autorun.bin
Attrib-s-h-r%windir%\system32\autorun.reg
Attrib-s-h-r%windir%\system32\autorun.txt
Attrib-s-h-r%windir%\system32\autorun.vbs
Attrib-s-h-r%windir%\system32\autorun.wsh
Del%windir%\system32\autorun.bat/q
Del%windir%\system32\autorun.bin/q
Del%windir%\system32\autorun.reg/q
Del%windir%\system32\autorun.txt/q
Del%windir%\system32\autorun.vbs/q
Del%windir%\system32\autorun.wsh/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.reg
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.bat
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.bin
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.txt
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.wsh
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul attrib-s-h-r%%d:\autorun.vbs
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.vbs/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.txt/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.reg/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.bin/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.wsh/q
FOR/D%%d in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do if exist%%d:\nul del%%d:\autorun.bat/q
attrib +s +h +r C:\NTDETECT.COM
REG ADD "hkcu\software\microsoft\windows\currentversion\explorer\advanced"/V showsuperhidden/t reg_dword/d 1/f
REG ADD "HKLM\Software\Microsoft\Windows nt\currentversion\winlogon\"/V userinit/d C:\WINDOWS\system32\ Userinit.exe, "/F
reg delete "HKCU\Software\Microsoft\Windows Script Host"/F
REG ADD "hkcu\software\microsoft\windows\currentversion\explorer\clsid\{645ff040-5081-101b-9f08-00aa002f954e}\ DefaultIcon "/V empty/t reg_expand_sz/d"%systemroot%\system32\shell32.dll,31 "/F
REG ADD "hkcu\software\microsoft\windows\currentversion\explorer\clsid\{645ff040-5081-101b-9f08-00aa002f954e}\ DefaultIcon "/V full/t reg_expand_sz/d"%systemroot%\system32\shell32.dll,32 "/F
Cls
set/p tmp= Press ENTER to begin resolving partitions cannot double hit open error.
@echo off
Title Yi Lin
Color 0a
Echo For example: D disk cannot be opened then enter D
set/p input=[Please enter the letter of the partition that cannot be opened]
if/i "%input%" = = "C" goto: Special
Attrib-s-h-r%input%:\autorun.inf
Cls
Del%input%:\autorun.inf/q
Cls
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"/V svohost/f
Cls
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL"/V checkedvalue/f
REM adds the correct "show hidden and files and folders" registry entry.
REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL"/V checkedvalue/t REG_DWORD/D 1/f
Cls
Chkdsk%input%:/f/x
Cls
set/p The tmp= operation ends, press ENTER to exit the program.
: Exit
Exit
: Special
Attrib-s-h-r%input%:\autorun.inf
Del%input%:\autorun.inf/q
The echo operation ends successfully, please reboot, and then double-click to open it.
echo If you restart, still can't double click Open, explain your computer
There is also a virus in Echo, please antivirus first. Then run the program again.
set/p The tmp= operation ends, press ENTER to exit the program.


2. Double-click to run *.bat file, follow the steps
This method absolutely works!
Not directly q me!
I'm sure I'm not struggling!

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.