|
这是我做的delvir.bat。有一部分是自己写的。还有好大一部分是从红叶那里拷过来的
@echo off
cls
color 2f
echo.
echo.
echo 清除系统垃圾文件
echo.
echo 按任意键开始清除……
pause>nul
echo 正在清除系统垃圾文件,请稍等......
del /f /s /q /a %systemdrive%\*.tmp
del /f /s /q %systemdrive%\*._mp
del /f /s /q %systemdrive%\*.log
del /f /s /q %systemdrive%\*.gid
del /f /s /q %systemdrive%\*.chk
del /f /s /q %systemdrive%\*.old
del /f /s /q %systemdrive%\desktop.ini
del /f /s /q /a %systemdrive%\recycled\*.*
del /f /s /q %windir%\*.bak
del /f /s /q %windir%\prefetch\*.*
rd /s /q %windir%\temp & md %windir%\temp
del /f /q "%userprofile%\Cookies\*.*"
del /f /q /s "%userprofile%\recent\*.*"
del /f /s /q /a "%userprofile%\Local Settings\Temporary Internet Files\*.*"
del /f /s /q /a "%userprofile%\Local Settings\Temp\*.*"
del /f /q /a "%SystemDrive%\Documents and Settings\*.com"
del /f /q /a "%SystemDrive%\Documents and Settings\*.exe"
del /f /q /a "%SystemDrive%\Documents and Settings\*.dll"
del /f /q /a "%SystemDrive%\Documents and Settings\*.pif"
del /f /q /a "%SystemDrive%\Documents and Settings\*.bat"
del /f /q /a "%SystemDrive%\Documents and Settings\*.reg"
del /f /q /a "%SystemDrive%\Documents and Settings\*.htt"
del /f /q /a "%SystemDrive%\Documents and Settings\*.scr"
del /f /q /a "%SystemDrive%\Documents and Settings\*.pif"
del /f /q /a "%SystemDrive%\Documents and Settings\*.sys"
del /f /q /a "%SystemDrive%\Documents and Settings\*.cab"
del /f /q /a "%SystemDrive%\Documents and Settings\*.ocx"
del /f /q /a "%SystemDrive%\Documents and Settings\*.hta"
del /f /q /a "%ProgramFiles%\*.com"
del /f /q /a "%ProgramFiles%\*.exe"
del /f /q /a "%ProgramFiles%\*.dll"
del /f /q /a "%ProgramFiles%\*.pif"
del /f /q /a "%ProgramFiles%\*.bat"
del /f /q /a "%ProgramFiles%\*.reg"
del /f /q /a "%ProgramFiles%\*.htt"
del /f /q /a "%ProgramFiles%\*.hta"
del /f /q /a "%ProgramFiles%\*.scr"
del /f /q /a "%ProgramFiles%\*.sys"
del /f /q /a "%ProgramFiles%\*.cab"
del /f /q /a "%ProgramFiles%\*.ocx"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.com"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.pif"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.bat"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.reg"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\?.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*0*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*1*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*2*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*3*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*4*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*5*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*6*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*7*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*8*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*9*.exe"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.sys"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.htt"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.hta"
del /f /q /a /s "%ProgramFiles%\Internet Explorer\*.ocx"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.com"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.pif"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.bat"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.reg"
del /f /q /a /s "%ProgramFiles%\Outlook Express\?.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*1*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*2*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*3*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*4*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*6*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*7*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*8*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*9*.exe"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.sys"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.htt"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.hta"
del /f /q /a /s "%ProgramFiles%\Outlook Express\*.ocx"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.com"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.pif"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.bat"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.reg"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\?.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*0*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*1*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*3*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*4*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*5*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*6*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*7*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*8*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*9*.exe"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.sys"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.htt"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.hta"
del /f /q /a /s "%ProgramFiles%\Windows Media Player\*.ocx"
del /f /q /a "%commonprogramfiles%\*.com"
del /f /q /a "%commonprogramfiles%\*.exe"
del /f /q /a "%commonprogramfiles%\*.dll"
del /f /q /a "%commonprogramfiles%\*.pif"
del /f /q /a "%commonprogramfiles%\*.bat"
del /f /q /a "%commonprogramfiles%\*.reg"
del /f /q /a "%commonprogramfiles%\*.sys"
del /f /q /a "%commonprogramfiles%\*.htt"
del /f /q /a "%commonprogramfiles%\*.hta"
del /f /q /a "%commonprogramfiles%\*.cab"
del /f /q /a "%commonprogramfiles%\*.ocx"
del /f /q /a %windir%\*.com
del /f /q /a %windir%\*.bat
del /f /q /a %windir%\*.reg
del /f /q /a %windir%\?.exe
del /f /q /a %windir%\*4*.exe
del /f /q /a %windir%\*5*.exe
del /f /q /a %windir%\*6*.exe
del /f /q /a %windir%\*7*.exe
del /f /q /a %windir%\*8*.exe
del /f /q /a %windir%\*9*.exe
del /f /q /a %windir%\*0*.exe
del /f /q /a %windir%\*.htt
del /f /q /a %windir%\*.hta
del /f /q /a %windir%\*.ocx
del /f /q /a %windir%\*.js
del /f /q /a %windir%\*.vbs
del /f /q /a %windir%\apppatch\*.com
del /f /q /a %windir%\apppatch\*.bat
del /f /q /a %windir%\apppatch\*.reg
del /f /q /a %windir%\apppatch\*.sys
del /f /q /a %windir%\apppatch\*.htt
del /f /q /a %windir%\apppatch\*.hta
del /f /q /a %windir%\apppatch\*.ocx
del /f /q /a %windir%\apppatch\*.js
del /f /q /a %windir%\apppatch\*.vbs
del /f /q /a %windir%\apppatch\?.exe
del /f /q /a %windir%\apppatch\*0*.exe
del /f /q /a %windir%\apppatch\*1*.exe
del /f /q /a %windir%\apppatch\*2*.exe
del /f /q /a %windir%\apppatch\*3*.exe
del /f /q /a %windir%\apppatch\*4*.exe
del /f /q /a %windir%\apppatch\*5*.exe
del /f /q /a %windir%\apppatch\*6*.exe
del /f /q /a %windir%\apppatch\*7*.exe
del /f /q /a %windir%\apppatch\*8*.exe
del /f /q /a %windir%\apppatch\*9*.exe
del /f /q /a %windir%\Config\*.com
del /f /q /a %windir%\Config\*.exe
del /f /q /a %windir%\Config\*.dll
del /f /q /a %windir%\Config\*.pif
del /f /q /a %windir%\Config\*.bat
del /f /q /a %windir%\Config\*.reg
del /f /q /a %windir%\Config\*.htt
del /f /q /a %windir%\Config\*.hta
del /f /q /a %windir%\Config\*.js
del /f /q /a %windir%\Config\*.vbs
del /f /q /a %windir%\Config\*.ocx
del /f /q /a %windir%\Config\*.sys
del /f /q /a %windir%\Config\*.scr
del /f /q /a %windir%\Cursors\*.com
del /f /q /a %windir%\Cursors\*.exe
del /f /q /a %windir%\Cursors\*.dll
del /f /q /a %windir%\Cursors\*.pif
del /f /q /a %windir%\Cursors\*.bat
del /f /q /a %windir%\Cursors\*.reg
del /f /q /a %windir%\Cursors\*.htt
del /f /q /a %windir%\Cursors\*.hta
del /f /q /a %windir%\Cursors\*.js
del /f /q /a %windir%\Cursors\*.vbs
del /f /q /a %windir%\Cursors\*.ocx
del /f /q /a %windir%\Cursors\*.sys
del /f /q /a %windir%\Cursors\*.scr
del /f /q /a %windir%\debug\*.com
del /f /q /a %windir%\debug\*.exe
del /f /q /a %windir%\debug\*.dll
del /f /q /a %windir%\debug\*.pif
del /f /q /a %windir%\debug\*.bat
del /f /q /a %windir%\debug\*.reg
del /f /q /a %windir%\debug\*.htt
del /f /q /a %windir%\debug\*.hta
del /f /q /a %windir%\debug\*.js
del /f /q /a %windir%\debug\*.vbs
del /f /q /a %windir%\debug\*.ocx
del /f /q /a %windir%\debug\*.sys
del /f /q /a %windir%\debug\*.scr
del /f /q /a /s "%windir%\Downloaded Program Files\*.com"
del /f /q /a /s "%windir%\Downloaded Program Files\*.exe"
del /f /q /a /s "%windir%\Downloaded Program Files\*.pif"
del /f /q /a /s "%windir%\Downloaded Program Files\*.bat"
del /f /q /a /s "%windir%\Downloaded Program Files\*.reg"
del /f /q /a /s "%windir%\Downloaded Program Files\*.htt"
del /f /q /a /s "%windir%\Downloaded Program Files\*.hta"
del /f /q /a /s "%windir%\Downloaded Program Files\*.js"
del /f /q /a /s "%windir%\Downloaded Program Files\*.vbs"
del /f /q /a /s "%windir%\Downloaded Program Files\*.sys"
del /f /q /a /s "%windir%\Downloaded Program Files\*.scr"
del /f /q /a /s "%windir%\Driver Cache\*.com"
del /f /q /a /s "%windir%\Driver Cache\*.exe"
del /f /q /a /s "%windir%\Driver Cache\*.dll"
del /f /q /a /s "%windir%\Driver Cache\*.pif"
del /f /q /a /s "%windir%\Driver Cache\*.bat"
del /f /q /a /s "%windir%\Driver Cache\*.reg"
del /f /q /a /s "%windir%\Driver Cache\*.htt"
del /f /q /a /s "%windir%\Driver Cache\*.hta"
del /f /q /a /s "%windir%\Driver Cache\*.js"
del /f /q /a /s "%windir%\Driver Cache\*.vbs"
del /f /q /a /s "%windir%\Driver Cache\*.ocx"
del /f /q /a /s "%windir%\Driver Cache\*.sys"
del /f /q /a /s "%windir%\Driver Cache\*.scr"
del /f /q /a %windir%\fonts\*.com
del /f /q /a %windir%\fonts\*.exe
del /f /q /a %windir%\fonts\*.dll
del /f /q /a %windir%\fonts\*.pif
del /f /q /a %windir%\fonts\*.bat
del /f /q /a %windir%\fonts\*.reg
del /f /q /a %windir%\fonts\*.htt
del /f /q /a %windir%\fonts\*.hta
del /f /q /a %windir%\fonts\*.js
del /f /q /a %windir%\fonts\*.vbs
del /f /q /a %windir%\fonts\*.ocx
del /f /q /a %windir%\fonts\*.sys
del /f /q /a %windir%\fonts\*.scr
del /f /q /a %windir%\help\*.com
del /f /q /a %windir%\help\*.exe
del /f /q /a %windir%\help\*.dll
del /f /q /a %windir%\help\*.pif
del /f /q /a %windir%\help\*.bat
del /f /q /a %windir%\help\*.reg
del /f /q /a %windir%\help\*.htt
del /f /q /a %windir%\help\*.hta
del /f /q /a %windir%\help\*.js
del /f /q /a %windir%\help\*.vbs
del /f /q /a %windir%\help\*.ocx
del /f /q /a %windir%\help\*.sys
del /f /q /a %windir%\help\*.scr
del /f /q /a %windir%\inf\*.com
del /f /q /a %windir%\inf\*.exe
del /f /q /a %windir%\inf\*.dll
del /f /q /a %windir%\inf\*.pif
del /f /q /a %windir%\inf\*.bat
del /f /q /a %windir%\inf\*.reg
del /f /q /a %windir%\inf\*.htt
del /f /q /a %windir%\inf\*.hta
del /f /q /a %windir%\inf\*.js
del /f /q /a %windir%\inf\*.vbs
del /f /q /a %windir%\inf\*.ocx
del /f /q /a %windir%\inf\*.sys
del /f /q /a %windir%\inf\*.scr
del /f /q /a %windir%\media\*.com
del /f /q /a %windir%\media\*.exe
del /f /q /a %windir%\media\*.dll
del /f /q /a %windir%\media\*.pif
del /f /q /a %windir%\media\*.bat
del /f /q /a %windir%\media\*.reg
del /f /q /a %windir%\media\*.htt
del /f /q /a %windir%\media\*.hta
del /f /q /a %windir%\media\*.js
del /f /q /a %windir%\media\*.vbs
del /f /q /a %windir%\media\*.ocx
del /f /q /a %windir%\media\*.sys
del /f /q /a %windir%\media\*.scr
del /F /Q /A "%windir%\Tasks\*.exe"
del /F /Q /A "%windir%\Tasks\*.pif"
del /F /Q /A "%windir%\Tasks\*.com"
del /F /Q /A "%windir%\Tasks\*.bat"
del /F /Q /A "%windir%\Tasks\*.job"
del /f /q /a %windir%\web\*.com
del /f /q /a %windir%\web\*.exe
del /f /q /a %windir%\web\*.dll
del /f /q /a %windir%\web\*.pif
del /f /q /a %windir%\web\*.bat
del /f /q /a %windir%\web\*.reg
del /f /q /a %windir%\web\*.sys
del /f /q /a %windir%\web\*.ocx
del /f /q /a %windir%\web\*.js
del /f /q /a %windir%\web\*.vbs
del /f /q /a /s %windir%\WinSxS\*.com
del /f /q /a /s %windir%\WinSxS\*.exe
del /f /q /a /s %windir%\WinSxS\*.pif
del /f /q /a /s %windir%\WinSxS\*.bat
del /f /q /a /s %windir%\WinSxS\*.reg
del /f /q /a /s %windir%\WinSxS\*.sys
del /f /q /a /s %windir%\WinSxS\*.ocx
del /f /q /a /s %windir%\WinSxS\*.js
del /f /q /a /s %windir%\WinSxS\*.vbs
del /f /q /a /s %windir%\WinSxS\*.scr
del /f /q /a %windir%\WinSxS\*.dll
del /f /s /q /a %windir%\system\*.com
del /f /s /q /a %windir%\system\*.bat
del /f /s /q /a %windir%\system\*.pif
del /f /s /q /a %windir%\system\*.reg
del /f /s /q /a %windir%\system\*.htt
del /f /s /q /a %windir%\system\*.hta
del /f /s /q /a %windir%\system\*.sys
del /f /s /q /a %windir%\system\*.ocx
del /f /s /q /a %windir%\system\*.js
del /f /s /q /a %windir%\system\*.vbs
del /f /s /q /a %windir%\system\*.scr
del /f /s /q /a %windir%\system32\dllcache\*.com
del /f /s /q /a %windir%\system32\dllcache\*.pif
del /f /s /q /a %windir%\system32\dllcache\*.bat
del /f /s /q /a %windir%\system32\dllcache\*.reg
del /f /s /q /a %windir%\system32\dllcache\*.htt
del /f /s /q /a %windir%\system32\dllcache\*.hta
del /f /s /q /a %windir%\system32\dllcache\*.js
del /f /s /q /a %windir%\system32\dllcache\*.vbs
del /f /s /q /a %windir%\system32\dllcache\*.scr
del /f /s /q /a %windir%\system32\WBEM\*.com
del /f /s /q /a %windir%\system32\WBEM\*.sys
del /f /s /q /a %windir%\system32\WBEM\*.pif
del /f /s /q /a %windir%\system32\WBEM\*.js
del /f /s /q /a %windir%\system32\WBEM\*.vbs
del /f /s /q /a %windir%\system32\WBEM\*.htt
del /f /s /q /a %windir%\system32\WBEM\*.hta
del /f /q /a %windir%\system32\drivers\*.com
del /f /q /a %windir%\system32\drivers\*.exe
del /f /q /a %windir%\system32\drivers\*.bat
del /f /q /a %windir%\system32\drivers\*.reg
del /f /q /a %windir%\system32\drivers\*.htt
del /f /q /a %windir%\system32\drivers\*.hta
del /f /q /a %windir%\system32\drivers\*.ocx
del /f /q /a %windir%\system32\drivers\*.js
del /f /q /a %windir%\system32\drivers\*.vbs
del /f /q /a %windir%\system32\drivers\*.scr
del /f /q /a %windir%\system32\drivers\etc\*.com
del /f /q /a %windir%\system32\drivers\etc\*.exe
del /f /q /a %windir%\system32\drivers\etc\*.dll
del /f /q /a %windir%\system32\drivers\etc\*.pif
del /f /q /a %windir%\system32\drivers\etc\*.bat
del /f /q /a %windir%\system32\drivers\etc\*.reg
del /f /q /a %windir%\system32\drivers\etc\*.htt
del /f /q /a %windir%\system32\drivers\etc\*.hta
del /f /q /a %windir%\system32\drivers\etc\*.js
del /f /q /a %windir%\system32\drivers\etc\*.vbs
del /f /q /a %windir%\system32\drivers\etc\*.ocx
del /f /q /a %windir%\system32\drivers\etc\*.scr
del /f /q /a %windir%\system32\drivers\etc\*.sys
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\Autorun.*>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.pif>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.htt>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.hta>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.vbs>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.js>nul 2>nul
for %%a in (e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.bat>nul 2>nul
for %%a in (e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.com>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.dll>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.scr>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.reg>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.vbe>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.jse>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.wsf>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\*.wsh>nul 2>nul
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do del /f /q /a:s %%a:\?.exe>nul 2>nul
rem 如果程序目录变量不在C:区则对C:区程序目录也操作删除一次!
rem 因为某些恶意的安装目录不是使用系统变量,而是使用绝对的C盘路径。
echo %ProgramFiles%|find "C:">nul&&goto :prg
for /f "delims=" %%a in (prg.txt) do (
del /A /F /Q "C:\Program Files\%%a">nul 2>nul
:prg
echo 正在删除默认程序目录 Program Files 目录……
for /f "delims=" %%a in (prg.txt) do (
del /A /F /Q "%ProgramFiles%\%%a">nul 2>nul
echo 正在删除 System32 目录……
for /f "delims=" %%a in (Sys.txt) do (
del /A /F /Q "%SystemRoot%\System32\%%a">nul 2>nul
rem win
echo 正在删除 Windows/WinNT 目录……
for /f "delims=" %%a in (Win.txt) do (
del /A /F /Q "%SystemRoot%\%%a">nul 2>nul
rem sysdrive
echo 正在删除磁盘根目录恶意软件……
for /f "delims=" %%a in (sysdrive.txt) do (
del /A /F /Q "%systemdrive%\%%a">nul 2>nul
rem 清除喜欢利用回收站的移动磁盘自动运行病毒
for %%a in (c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z) do (
for %%b in (exe pif com) do echo Y|cacls "%%a:\Recycler\*.%%b" /C /T /P everyone:F>nul 2>nul&echo Y|cacls "%%a:\Recycled\*.%%b" /C /T /P everyone:F>nul 2>nul
(
for %%b in (exe pif com) do del /A /F /S /Q "%%a:\Recycled\*.%%b">nul 2>nul&del /A /F /S /Q "%%a:\Recycled\Recycled\*.%%b"
))>nul 2>nul
rem 清理并免疫启动组
echo Y|cacls "%USERPROFILE%\「开始」菜单\程序\启动" /C /P everyone:F>nul 2>nul
echo Y|cacls "%ALLUSERSPROFILE%\「开始」菜单\程序\启动" /C /P everyone:F>nul 2>nul
for %%a in (exe pif com) do attrib -s -h -r "%USERPROFILE%\「开始」菜单\程序\启动\*.%%a">nul 2>nul
for %%a in (exe pif com) do attrib -s -h -r "%ALLUSERSPROFILE%\「开始」菜单\程序\启动\*.%%a">nul 2>nul
for %%a in (exe pif com) do del /A /F /S /Q "%USERPROFILE%\「开始」菜单\程序\启动\*.%%a">nul 2>nul
for %%a in (exe pif com) do del /A /F /S /Q "%ALLUSERSPROFILE%\「开始」菜单\程序\启动\*.%%a">nul 2>nul
echo Y|cacls "%USERPROFILE%\「开始」菜单\程序\启动" /C /P everyone:R>nul 2>nul
echo Y|cacls "%ALLUSERSPROFILE%\「开始」菜单\程序\启动" /C /P everyone:R>nul 2>nul
echo 正在检查并恢复相关注册表默认值……
rem 取消在资源管理器中彻底隐藏文件、禁止文件、禁止CMD、禁止注册表编辑器,禁止文件夹选项、禁止任务管理器等
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v CheckedValue /t REG_DWORD /d 0x00000001 /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFolderOptions /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableCMD /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /t REG_SZ /d Explorer.exe /f>nul 2>nul
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot" /v AlternateShell /t REG_SZ /d cmd.exe /f>nul 2>nul
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"|findstr /i "Explorer\DisallowRun">nul&&for /f %%a in ('reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun"^|findstr /i "regedit.exe taskmgr.exe IceSword.exe FolderSniffer.exe msconfig.exe wsyscheck.exe ArSwp.exe SREngPS.EXE"') do reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun" /v %%a /f>nul 2>nul
Rem 无条件禁止所有磁盘自动运行特性防范自动运行病毒
reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveAutoRun /t REG_BINARY /d ffffff03 /f>nul 2>nul
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
reg add "HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
reg add "HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
reg add "HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
reg add "HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 0x000000ff /f>nul 2>nul
rem 停止并禁用外壳播放事件通知服务
sc stop ShellHWDetection >nul 2>nul
sc config ShellHWDetection start= disabled >nul 2>nul
rem 添加防止从回收站或仿回收站的目录中直接运行可执行文件的策略
set REGPATH=HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths
set SFLAG=/v SaferFlags /t REG_DWORD /d 0x00000000 /f
set IDATA=/f /v ItemData /d "?:\Recyc?
reg add %REGPATH%\{00ffa5bf-abe7-4901-aacf-4f58aa31217a} %SFLAG%>nul
reg add %REGPATH%\{00ffa5bf-abe7-4901-aacf-4f58aa31217a} %IDATA%\*\*\*\*.*">nul
reg add %REGPATH%\{41fe7eed-c47a-46f6-840a-240796fd03cf} %SFLAG%>nul
reg add %REGPATH%\{41fe7eed-c47a-46f6-840a-240796fd03cf} %IDATA%\*\*\*.*">nul
reg add %REGPATH%\{4e93c91c-a40e-462e-9b89-3b0832d222d9} %SFLAG%>nul
reg add %REGPATH%\{4e93c91c-a40e-462e-9b89-3b0832d222d9} %IDATA%\*.*">nul
reg add %REGPATH%\{5bfc100b-d3fb-450e-88ec-6819ab56a9ff} %SFLAG%>nul
reg add %REGPATH%\{5bfc100b-d3fb-450e-88ec-6819ab56a9ff} %IDATA%\*\*\*\*.*">nul
reg add %REGPATH%\{5c5e2bcd-7057-43f4-830c-e4361d2afadd} %SFLAG%>nul
reg add %REGPATH%\{5c5e2bcd-7057-43f4-830c-e4361d2afadd} %IDATA%\*.*">nul
reg add %REGPATH%\{5f8ff865-0638-4c6e-98de-923e7bc6b330} %SFLAG%>nul
reg add %REGPATH%\{5f8ff865-0638-4c6e-98de-923e7bc6b330} %IDATA%\*\*\*.*">nul
reg add %REGPATH%\{649c1429-0e79-453c-abe9-b5682e035ae7} %SFLAG%>nul
reg add %REGPATH%\{649c1429-0e79-453c-abe9-b5682e035ae7} %IDATA%\*\*.*">nul
reg add %REGPATH%\{718f54b2-c669-4d7b-aeff-18d69f100034} %SFLAG%>nul
reg add %REGPATH%\{718f54b2-c669-4d7b-aeff-18d69f100034} %IDATA%\*\*.*">nul
reg add %REGPATH%\{8385d9d2-80c9-4ac1-a100-ed3e62863d97} %SFLAG%>nul
reg add %REGPATH%\{8385d9d2-80c9-4ac1-a100-ed3e62863d97} %IDATA%\*.*">nul
reg add %REGPATH%\{af2a4fcf-441c-421e-9663-52cd3502cfd7} %SFLAG%>nul
reg add %REGPATH%\{af2a4fcf-441c-421e-9663-52cd3502cfd7} %IDATA%\*\*\*.*">nul
reg add %REGPATH%\{b997f4b2-c037-4e97-b051-31f5d86df802} %SFLAG%>nul
reg add %REGPATH%\{b997f4b2-c037-4e97-b051-31f5d86df802} %IDATA%\*\*.*">nul
reg add %REGPATH%\{d4e7b6ff-d76f-407f-b8bb-ea0835f5babc} %SFLAG%>nul
reg add %REGPATH%\{d4e7b6ff-d76f-407f-b8bb-ea0835f5babc} /f /v ItemData /d "RECYC*.*">nul
rem 防止碎片文档类型
reg delete "HKCR\ShellScrap\shell\open\command" /f >nul 2>nul
reg add "HKCR\ShellScrap\shell\open\command" >nul 2>nul
echo 清除IE地址栏栏垃圾
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\TypeURLs" /f>nul 2>nul
rem 本键值不能锁定,只能恢复正常值。否则将导致不能引导。
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /f>nul 2>nul
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /d Explorer.exe /f>nul 2>nul
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v UIHost /f>nul 2>nul
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v UIHost /d logonui.exe /f>nul 2>nul
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f>nul 2>nul
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /d "%SystemRoot%\system32\userinit.exe," /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v VmApplet /t REG_SZ /d "rundll32 shell32,Control_RunDLL "sysdm.cpl"" /f>nul 2>nul
echo 还原 IE 的所有默认设置……
rem HKLM
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /d about:blank /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Search_URL" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Search_URL" /d "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Local Page" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Local Page" /d about:blank /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /d "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /d about:blank /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /v "CustomizeSearch" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /v "CustomizeSearch" /d "http://www.google.com" /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /v "SearchAssistant" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /v "SearchAssistant" /d "http://ie.search.msn.com/{SUB_RFC1766}/scrhasst/scrhasst.htm" /f>nul 2>nul
rem LKCU
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /d about:blank /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Search_URL" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Default_Search_URL" /d "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Local Page" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Local Page" /d about:blank /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /d "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /d about:blank /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Search" /v "CustomizeSearch" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Search" /v "CustomizeSearch" /d "http://www.google.com" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Search" /v "SearchAssistant" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\Search" /v "SearchAssistant" /d "http://ie.search.msn.com/{SUB_RFC1766}/scrhasst/scrhasst.htm" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /v "provider" /f>nul 2>nul
reg add "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /v "provider" /d "" /f>nul 2>nul
reg delete "HKLM\Software\Microsoft\Internet Explorer\Extensions" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\Extensions" /f>nul 2>nul
reg add "HKLM\Software\Microsoft\Internet Explorer\Extensions" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\Extensions" /f>nul 2>nul
reg delete "HKLM\Software\Microsoft\Internet Explorer\Toolbar" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar" /f>nul 2>nul
reg add "HKLM\Software\Microsoft\Internet Explorer\Toolbar" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\Toolbar" /f>nul 2>nul
reg delete "HKLM\Software\Microsoft\Internet Explorer\MenuExt" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt" /f>nul 2>nul
reg add "HKLM\Software\Microsoft\Internet Explorer\MenuExt" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\MenuExt" /f>nul 2>nul
reg delete "HKLM\Software\Microsoft\Internet Explorer\MenuExt2" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt2" /f>nul 2>nul
reg add "HKLM\Software\Microsoft\Internet Explorer\MenuExt2" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\MenuExt2" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix" /ve /d "http://" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes" /v ftp /d "ftp://" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes" /v www /d "http://" /f>nul 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Browser Helper Objects" /f>nul 2>nul
reg delete "HKCU\SOFTWARE\Microsoft\Internet Explorer\Browser Helper Objects" /f>nul 2>nul
reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Browser Helper Objects" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\TypedUrls" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\TypedUrls" /f>nul 2>nul
reg delete "HKCU\Software\Microsoft\Internet Explorer\TypeURLs" /f>nul 2>nul
reg add "HKCU\Software\Microsoft\Internet Explorer\TypeURLs" /f>nul 2>nul
echo 正在检测并清除部分恶意病毒的注册表残留……
%SystemRoot%\regedit.exe /s Regdel.reg
echo 过期图标清理
taskkill /f /im explorer.exe>nul 2>nul
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify" /va /f
start explorer
echo 清除系统垃圾完成,任意键退出!
pause>nul |
|