在安全模式下运行 delwnso.bat
delwnso.bat
del "C:/WINDOWS/system32/drivers/front.sys"
del "C:/WINDOWS/system32/drivers/roreg.sys"
regedit /s delwnso.reg
del "C:/WINDOWS/system32/drivers/roreg.sys"
regedit /s delwnso.reg
del "C:/windows/system/*.exe" /Q
del "%SystemRoot%/system/96498c7f/*.*" /Q
del "%SystemRoot%/system/96498c7f/*.*" /Q
del "%USERPROFILE%/Local Settings/Temp/*.*" /Q
del "%USERPROFILE%/Templates/75316a1/*.*" /Q
del "%ALLUSERSPROFILE%/「开始」菜单/程序/启动/WNSO.lnk"
del "%USERPROFILE%/Templates/75316a1/*.*" /Q
del "%ALLUSERSPROFILE%/「开始」菜单/程序/启动/WNSO.lnk"
del "C:/Program Files/Common Files/RGGZS/*.*" /Q
del "C:/Program Files/Common Files/RGGZS/res/*.*" /Q
del "C:/Program Files/Common Files/RGGZS/res/*.*" /Q
delwnso.reg
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/front]
@=""
[-HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/roreg]
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run]
"wk"=-
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer/Run]
"wk"=-
@=""
[-HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/roreg]
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run]
"wk"=-
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer/Run]
"wk"=-