|
@echo off
arp -d
arp -s 192.168.0.1 00-02-A5-41-DF-93
taskkill /f /im realsched.exe
ren "C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll" ierpplug.dlxxx
regsvr32 /u /s "C:\Program Files\Common Files\System\msadc\msadco.dll"
ren "C:\Program Files\Common Files\System\msadc\msadco.dll" msadco.dlxxx
\\copy \\192.168.0.248\启动BAT\杀毒 C:\WINDOWS\system32\drivers\etc
copy \\192.168.0.248\启动BAT\桌面 C:\docume~1\ztlw\桌面
Start C:\docume~1\ztlw\桌面\killer_rodog.exe -anti
copy \\192.168.0.248\启动BAT\启动\ARP本机绑定.bat C:\docume~1\ztlw\
Start C:\docume~1\ztlw\ARP本机绑定.bat -anti
copy \\192.168.0.248\启动BAT\启动\ARPKiller.exe C:\docume~1\ztlw\
Start C:\docume~1\ztlw\ARPKiller.exe -anti
md %SystemRoot%\system32\userinit.exe >nul 2>nul
attrib +s +r +h +a %SystemRoot%\system32\userinit.exe
md %systemroot%\system32\drivers\pcihdd.sys
cacls %systemroot%\system32\drivers\pcihdd.sys /e /p everyone:n
cacls %systemroot%\system32\userinit.exe /e /p everyone:r
md "c:\WINDOWS\ljdxij.exe"
md "c:\WINDOWS\wtlnlm.exe"
md "c:\WINDOWS\issfkt.exe"
md "c:\WINDOWS\fcexnn.exe"
md "c:\WINDOWS\system32\com\heii3.exe"
md "c:\WINDOWS\system32\crugd.dll"
md "c:\WINDOWS\system32\popo.exe"
md "c:\WINDOWS\system32\.exe"
md "c:\WINDOWS\System32\wbem\SAChost.exe"
md "c:\WINDOWS\realname.dat"
md "c:\WINDOWS\wsockd~1.dll"
md "c:\WINDOWS\system32\qoq.exe"
md "c:\WINDOWS\system32\drivers\pcihdd.sys"
md "c:\WINDOWS\cinfonmc.exe"
md "c:\RavMon.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\.exe"
md "c:\WINDOWS\help\help.dll"
md "c:\WINDOWS\ljdxij.exe"
md "c:\WINDOWS\uehizt.exe"
md "c:\WINDOWS\gfmexd.exe"
md "c:\WINDOWS\wxhvku.exe"
md "c:\WINDOWS\sopkfi.exe"
md "c:\WINDOWS\xgcqbj.exe"
md "c:\WINDOWS\iqullt.exe"
md "c:\WINDOWS\iftewb.exe"
md "c:\WINDOWS\gwleja.exe"
md "c:\WINDOWS\acrozr.exe"
md "c:\WINDOWS\dpvwfz.exe"
md "c:\WINDOWS\flhmmz.exe"
md "c:\WINDOWS\hglutz.exe"
md "c:\WINDOWS\nmrqsi.exe"
md "c:\WINDOWS\kootyn.exe"
md "c:\WINDOWS\nbrcnv.exe"
md "c:\WINDOWS\nuoayw.exe"
md "c:\WINDOWS\rnjief.exe"
md "c:\WINDOWS\qzrrjp.exe"
md "c:\WINDOWS\qzrrjp.exe"
md "c:\WINDOWS\dhlior.exe"
md "c:\WINDOWS\soundman.exe"
md "c:\WINDOWS\ptxzpb.exe"
md "c:\WINDOWS\vdlqnt.exe"
md "c:\WINDOWS\gqhsnd.exe"
md "c:\WINDOWS\pwebgd.exe"
md "c:\WINDOWS\ehrdpp.exe"
md "c:\WINDOWS\wnngqb.exe"
md "c:\WINDOWS\leowis.exe"
md "c:\WINDOWS\igfbql.exe"
md "c:\WINDOWS\lsleeb.exe"
md "c:\WINDOWS\aunklc.exe"
md "c:\WINDOWS\xxexbv.exe"
md "c:\WINDOWS\rmziuv.exe"
md "c:\WINDOWS\zvdthx.exe"
md "c:\WINDOWS\jthvda.exe"
md "c:\WINDOWS\zswwuz.exe"
md "c:\WINDOWS\lxzeyo.exe"
md "c:\WINDOWS\hmhknd.exe"
md "c:\WINDOWS\zkxsko.exe"
md "c:\WINDOWS\ljxqdc.exe"
md "c:\WINDOWS\onzdrm.exe"
md "c:\WINDOWS\txotuk.exe"
md "c:\WINDOWS\pxdyff.exe"
md "c:\WINDOWS\kjctdg.exe"
md "c:\WINDOWS\yqynyq.exe"
md "c:\WINDOWS\kktmdt.exe"
md "c:\WINDOWS\evsocv.exe"
md "c:\WINDOWS\zhrrbw.exe"
md "c:\WINDOWS\thfqmh.exe"
md "c:\WINDOWS\iyudtt.exe"
md "c:\WINDOWS\stukfs.exe"
md "c:\WINDOWS\suddxx.exe"
md "c:\WINDOWS\yqynyq.exe"
md "c:\WINDOWS\uipokk.exe"
md "c:\WINDOWS\lkpkyd.exe"
md "c:\WINDOWS\yqynyq.exe"
md "c:\WINDOWS\HBKrnl.dll"
md "c:\WINDOWS\fiosectc.exe"
md "c:\WINDOWS\gnlakb.exe"
md "c:\WINDOWS\anistio.exe"
md "c:\WINDOWS\dionpis.exe"
md "c:\WINDOWS\hefcndy.exe"
md "c:\WINDOWS\tciocp32.exe"
md "c:\WINDOWS\fmsbbqi.exe"
md "c:\WINDOWS\bincdwsa.exe"
md "c:\WINDOWS\dbhlp32.exe"
md "c:\WINDOWS\fmsjhif.exe"
md "c:\WINDOWS\upzeqbwg.exe"
md "c:\WINDOWS\ptshell.exe"
md "c:\WINDOWS\ticisms.exe"
md "c:\WINDOWS\huifitc.exe"
md "c:\WINDOWS\yuiabct.exe"
md "c:\WINDOWS\dndsioc.exe"
md "c:\WINDOWS\fmbiost.exe"
md "c:\WINDOWS\system32\HBKrnl.dll"
md "c:\WINDOWS\system32\rsjzasp.exe"
md "c:\WINDOWS\system32\rsjzasp.exe"
md "c:\WINDOWS\system32\avzxmst.exe"
md "c:\WINDOWS\system32\okmhdaz.exe"
md "c:\WINDOWS\system32\kafykaz.exe"
md "c:\WINDOWS\system32\rpcs.exe"
md "c:\WINDOWS\system32\2.exe"
md "c:\WINDOWS\system32\kapjgaz.exe"
md "c:\WINDOWS\system32\3.exe"
md "c:\WINDOWS\system32\jsqxczc.exe"
md "c:\WINDOWS\system32\kkawdjaz.exe"
md "c:\WINDOWS\system32\kvdxmis.exe"
md "c:\WINDOWS\system32\kvdxsois.exe"
md "c:\WINDOWS\system32\mszxyll32.dll"
md "c:\WINDOWS\system32\nndcompress.dll"
md "c:\WINDOWS\system32\rsjzbsp.exe"
md "c:\WINDOWS\system32\starwindserviceae.exe"
md "c:\WINDOWS\GenProtect.exe"
md "c:\WINDOWS\qamd.exe"
md "c:\WINDOWS\xybvxx.exe"
md "c:\WINDOWS\wsnnpg.exe"
md "c:\WINDOWS\xirrab.exe"
md "c:\WINDOWS\ttykjv.exe"
md "c:\WINDOWS\fvaoxe.exe"
md "c:\WINDOWS\cectte.exe"
md "c:\WINDOWS\hkelnt.exe"
md "c:\WINDOWS\dh1.exe"
md "c:\WINDOWS\dh1.exe"
md "c:\WINDOWS\dh1.exe"
md "c:\WINDOWS\vuvakp.exe"
md "c:\WINDOWS\WSockDrv32.exe"
md "c:\WINDOWS\upxdnd.exe"
md "c:\WINDOWS\AVPSrv.exE"
md "c:\WINDOWS\cmdbcs.exe"
md "c:\WINDOWS\533931L.exe"
md "c:\WINDOWS\533931M.exe"
md "c:\WINDOWS\PTSShell.exe"
md "c:\WINDOWS\MsPrint32D.exe"
md "c:\WINDOWS\Kvsc3.exE"
md "c:\WINDOWS\SHAProc.exe"
md "c:\WINDOWS\system32\drivers\scvhost.exe"
md "c:\WINDOWS\mh.exe"
md "c:\WINDOWS\mh.exe"
md "c:\WINDOWS\mh.exe"
md "c:\1.exe"
md "c:\ntldr.exe"
md "c:\WINDOWS\system32\fpt.exe"
md "C:\windows\BEGIN.BAT"
md "C:\windows\help.dll"
md "c:\WINDOWS\system32\avwghst.exe"
md "c:\WINDOWS\system32\avwlist.exe"
md "c:\WINDOWS\system32\gjcsczc.exe"
md "c:\WINDOWS\system32\jsqsbzc.exe"
md "c:\WINDOWS\system32\jsqxazc.exe"
md "c:\WINDOWS\system32\jsqzczc.exe"
md "c:\WINDOWS\system32\kaqhlaz.exe"
md "c:\WINDOWS\system32\kawdiaz.exe"
md "c:\WINDOWS\system32\kvdxlis.exe"
md "c:\WINDOWS\system32\kvdxslis.exe"
md "c:\WINDOWS\system32\raqjktl.exe"
md "c:\WINDOWS\system32\rsmyjsp.exe"
md "c:\WINDOWS\system32\rsztnsp.exe"
md "c:\WINDOWS\system32\wszjdax.exe"
attrib "c:\WINDOWS\ljdxij.exe" +s +h +r
attrib "c:\WINDOWS\uehizt.exe" +s +h +r
attrib "c:\WINDOWS\hwnsff.exe" +s +h +r
attrib "c:\WINDOWS\gfmexd.exe" +s +h +r
attrib "c:\WINDOWS\wxhvku.exe" +s +h +r
attrib "c:\WINDOWS\sopkfi.exe" +s +h +r
attrib "c:\WINDOWS\xgcqbj.exe" +s +h +r
attrib "c:\WINDOWS\iqullt.exe" +s +h +r
attrib "c:\WINDOWS\iftewb.exe" +s +h +r
attrib "c:\WINDOWS\gwleja.exe" +s +h +r
attrib "c:\WINDOWS\acrozr.exe" +s +h +r
attrib "c:\WINDOWS\dpvwfz.exe" +s +h +r
attrib "c:\WINDOWS\flhmmz.exe" +s +h +r
attrib "c:\WINDOWS\hglutz.exe" +s +h +r
attrib "c:\WINDOWS\nmrqsi.exe" +s +h +r
attrib "c:\WINDOWS\kootyn.exe" +s +h +r
attrib "c:\WINDOWS\nbrcnv.exe" +s +h +r
attrib "c:\WINDOWS\nuoayw.exe" +s +h +r
attrib "c:\WINDOWS\rnjief.exe" +s +h +r
attrib "c:\WINDOWS\qzrrjp.exe" +s +h +r
attrib "c:\WINDOWS\qzrrjp.exe" +s +h +r
attrib "c:\WINDOWS\dhlior.exe" +s +h +r
attrib "c:\WINDOWS\wtlnlm.exe" +s +h +r
attrib "c:\WINDOWS\issfkt.exe" +s +h +r
attrib "c:\WINDOWS\fcexnn.exe" +s +h +r
attrib "c:\WINDOWS\system32\com\heii3.exe" +s +h +r
attrib "c:\WINDOWS\system32\crugd.dll" +s +h +r
attrib "c:\WINDOWS\realname.dat" +s +h +r
attrib "c:\WINDOWS\wsockd~1.dll" +s +h +r
attrib "c:\WINDOWS\system32\popo.exe" +s +h +r
attrib "c:\WINDOWS\\help\help.dll" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\dhlior.exe" +s +h +r
attrib "c:\WINDOWS\vdlqnt.exe" +s +h +r
attrib "c:\WINDOWS\HBKrnl.exe" +s +h +r
attrib "c:\WINDOWS\ptxzpb.exe" +s +h +r
attrib "c:\WINDOWS\vdlqnt.exe" +s +h +r
attrib "c:\WINDOWS\gqhsnd.exe" +s +h +r
attrib "c:\WINDOWS\pwebgd.exe" +s +h +r
attrib "c:\WINDOWS\ehrdpp.exe" +s +h +r
attrib "c:\WINDOWS\wnngqb.exe" +s +h +r
attrib "c:\WINDOWS\leowis.exe" +s +h +r
attrib "c:\WINDOWS\igfbql.exe" +s +h +r
attrib "c:\WINDOWS\lsleeb.exe" +s +h +r
attrib "c:\WINDOWS\aunklc.exe" +s +h +r
attrib "c:\WINDOWS\xxexbv.exe" +s +h +r
attrib "c:\WINDOWS\rmziuv.exe" +s +h +r
attrib "c:\WINDOWS\heii3.exe" +s +h +r
attrib "c:\WINDOWS\zvdthx.exe" +s +h +r
attrib "c:\WINDOWS\jthvda.exe" +s +h +r
attrib "c:\WINDOWS\zswwuz.exe" +s +h +r
attrib "c:\WINDOWS\lxzeyo.exe" +s +h +r
attrib "c:\WINDOWS\hmhknd.exe" +s +h +r
attrib "c:\WINDOWS\system32\crugd.dll" +s +h +r
attrib "c:\WINDOWS\system32\qoq.exe" +s +h +r
attrib "c:\WINDOWS\System32\wbem\SAChost.exe" +s +h +r
attrib "c:\WINDOWS\soundman.exe" +s +h +r
attrib "c:\WINDOWS\system32\drivers\pcihdd.sys" +s +h +r
attrib "c:\WINDOWS\cinfonmc.exe" +s +h +r
attrib "c:\RavMon.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\.exe" +s +h +r
attrib "c:\WINDOWS\CC.exe" +s +h +r
attrib "c:\WINDOWS\zkxsko.exe" +s +h +r
attrib "c:\WINDOWS\ljxqdc.exe" +s +h +r
attrib "c:\WINDOWS\onzdrm.exe" +s +h +r
attrib "c:\WINDOWS\txotuk.exe" +s +h +r
attrib "c:\WINDOWS\pxdyff.exe" +s +h +r
attrib "c:\WINDOWS\kjctdg.exe" +s +h +r
attrib "c:\WINDOWS\kktmdt.exe" +s +h +r
attrib "c:\WINDOWS\evsocv.exe" +s +h +r
attrib "c:\WINDOWS\zhrrbw.exe" +s +h +r
attrib "c:\WINDOWS\ynouwi.exe" +s +h +r
attrib "c:\WINDOWS\thfqmh.exe" +s +h +r
attrib "c:\WINDOWS\iyudtt.exe" +s +h +r
attrib "c:\WINDOWS\stukfs.exe" +s +h +r
attrib "c:\WINDOWS\suddxx.exe" +s +h +r
attrib "c:\WINDOWS\uipokk.exe" +s +h +r
attrib "c:\WINDOWS\lkpkyd.exe" +s +h +r
attrib "c:\WINDOWS\GenProtect.exE" +s +h +r
attrib "c:\WINDOWS\qamd.exe" +s +h +r
attrib "c:\WINDOWS\dh1.exe" +s +h +r
attrib "c:\WINDOWS\mh.exe" +s +h +r
attrib "c:\1.exe" +s +h +r
attrib "c:\ntldr.exe" +s +h +r
attrib "c:\WINDOWS\system32\fpt.exe" +s +h +r
attrib "C:\windows\BEGIN.BAT" +s +h +r
attrib "C:\windows\WSockDrv32.exe" +s +h +r
attrib "C:\windows\upxdnd.exe" +s +h +r
attrib "C:\windows\AVPSrv.exE" +s +h +r
attrib "C:\windows\cmdbcs.exe" +s +h +r
attrib "C:\windows\533931L.exe" +s +h +r
attrib "C:\windows\533931M.exe" +s +h +r
attrib "C:\windows\PTSShell.exe" +s +h +r
attrib "C:\windows\MsPrint32D.exe" +s +h +r
attrib "C:\windows\Kvsc3.exE" +s +h +r
attrib "C:\windows\hkelnt.exe" +s +h +r
attrib "C:\windows\vuvakp.exe" +s +h +r
attrib "C:\windows\xybvxx.exe" +s +h +r
attrib "C:\windows\wsnnpg.exe" +s +h +r
attrib "C:\windows\xirrab.exe" +s +h +r
attrib "C:\windows\ttykjv.exe" +s +h +r
attrib "C:\windows\fvaoxe.exe" +s +h +r
attrib "C:\windows\cectte.exe" +s +h +r
attrib "C:\windows\yqynyq.exe" +s +h +r
attrib "C:\windows\HBKrnl.dll" +s +h +r
attrib "C:\windows\fiosectc.exe" +s +h +r
attrib "C:\windows\gnlakb.exe" +s +h +r
attrib "C:\windows\anistio.exe" +s +h +r
attrib "C:\windows\dionpis.exe" +s +h +r
attrib "C:\windows\hefcndy.exe" +s +h +r
attrib "C:\windows\tciocp32.exe" +s +h +r
attrib "C:\windows\fmsbbqi.exe" +s +h +r
attrib "C:\windows\bincdwsa.exe" +s +h +r
attrib "C:\windows\dbhlp32.exe" +s +h +r
attrib "C:\windows\fmsjhif.exe" +s +h +r
attrib "C:\windows\upzeqbwg.exe" +s +h +r
attrib "C:\windows\ptshell.exe" +s +h +r
attrib "C:\windows\ticisms.exe" +s +h +r
attrib "C:\windows\huifitc.exe" +s +h +r
attrib "C:\windows\yuiabct.exe" +s +h +r
attrib "C:\windows\dndsioc.exe" +s +h +r
attrib "C:\windows\fmbiost.exe" +s +h +r
attrib "C:\windows\SHAProc.exe" +s +h +r
attrib "C:\windows\SHAProc.exe" +s +h +r
attrib "C:\windows\system32\drivers\scvhost.exe" +s +h +r
attrib "c:\WINDOWS\system32\avwghst.exe" +s +h +r
attrib "c:\WINDOWS\system32\HBKrnl.dll" +s +h +r
attrib "c:\WINDOWS\system32\avwlist.exe" +s +h +r
attrib "c:\WINDOWS\system32\gjcsczc.exe" +s +h +r
attrib "c:\WINDOWS\system32\jsqsbzc.exe" +s +h +r
attrib "c:\WINDOWS\system32\jsqxazc.exe" +s +h +r
attrib "c:\WINDOWS\system32\jsqzczc.exe" +s +h +r
attrib "c:\WINDOWS\system32\kaqhlaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\kawdiaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\kvdxlis.exe" +s +h +r
attrib "c:\WINDOWS\system32\raqjktl.exe" +s +h +r
attrib "c:\WINDOWS\system32\rsmyjsp.exe" +s +h +r
attrib "c:\WINDOWS\system32\rsztnsp.exe" +s +h +r
attrib "c:\WINDOWS\system32\wszjdax.exe" +s +h +r
attrib "c:\WINDOWS\system32\kvdxslis.exe" +s +h +r
attrib "c:\WINDOWS\system32\avwgjst.exe" +s +h +r
attrib "c:\WINDOWS\system32\kapjgaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\starwindserviceae.exe" +s +h +r
attrib "c:\WINDOWS\system32\rsjzbsp.exe" +s +h +r
attrib "c:\WINDOWS\system32\nndcompress.dll" +s +h +r
attrib "c:\WINDOWS\system32\mszxyll32.dll" +s +h +r
attrib "c:\WINDOWS\system32\kvdxsois.exe" +s +h +r
attrib "c:\WINDOWS\system32\kvdxmis.exe" +s +h +r
attrib "c:\WINDOWS\system32\kkawdjaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\jsqxczc.exe" +s +h +r
attrib "c:\WINDOWS\system32\rsjzasp.exe" +s +h +r
attrib "c:\WINDOWS\system32\avzxmst.exe" +s +h +r
attrib "c:\WINDOWS\system32\okmhdaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\kafykaz.exe" +s +h +r
attrib "c:\WINDOWS\system32\rpcs.exe" +s +h +r
attrib "c:\WINDOWS\system32\3.exe" +s +h +r
attrib "c:\WINDOWS\system32\HBKrnl.dll" +s +h +r
echo y|cacls.exe "c:\WINDOWS\GenProtect.exE" /d everyone
echo y|cacls.exe "c:\WINDOWS\vdlqnt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ljdxij.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\uehizt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hwnsff.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\gfmexd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\wxhvku.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\sopkfi.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\xgcqbj.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\iqullt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\iftewb.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\gwleja.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\acrozr.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dpvwfz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\flhmmz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hglutz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\nmrqsi.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\kootyn.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\nbrcnv.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\nuoayw.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\rnjief.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\qzrrjp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\qzrrjp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dhlior.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\CC.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\drivers\pcihdd.sys" /d everyone
echo y|cacls.exe "c:\RavMon.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\wtlnlm.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\issfkt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\fcexnn.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\com\heii3.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\crugd.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\realname.dat" /d everyone
echo y|cacls.exe "c:\WINDOWS\wsockd~1.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\qoq.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\System32\wbem\SAChost.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\popo.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\soundman.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\help\help.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\cinfonmc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\HBKrnl.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\ptxzpb.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\vdlqnt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\gqhsnd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\pwebgd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ehrdpp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\wnngqb.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\leowis.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\igfbql.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\lsleeb.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\aunklc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\xxexbv.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\rmziuv.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\zvdthx.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\jthvda.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\zswwuz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\lxzeyo.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hmhknd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\qamd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dh1.exe" /d everyon
echo y|cacls.exe "c:\WINDOWS\system32\drivers\scvhost.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\WSockDrv32.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\upxdnd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\AVPSrv.exE" /d everyone
echo y|cacls.exe "c:\WINDOWS\cmdbcs.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\533931L.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\533931M.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\PTSShell.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\MsPrint32D.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\Kvsc3.exE" /d everyone
echo y|cacls.exe "c:\WINDOWS\SHAProc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\mh.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\mh.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\vuvakp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\xybvxx.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\wsnnpg.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\xirrab.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ttykjv.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\fvaoxe.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\cectte.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\yqynyq.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\HBKrnl.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\fiosectc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\gnlakb.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\anistio.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dionpis.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hefcndy.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\tciocp32.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\fmsbbqi.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\bincdwsa.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dbhlp32.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\fmsjhif.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\upzeqbwg.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ptshell.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ticisms.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\huifitc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\yuiabct.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\dndsioc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\fmbiost.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\heii3.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\zkxsko.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ljxqdc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\onzdrm.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\txotuk.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\kjctdg.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\kktmdt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\evsocv.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\zhrrbw.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\ynouwi.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\thfqmh.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\iyudtt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\stukfs.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\suddxx.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\uipokk.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\lkpkyd.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hkelnt.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\hkelnt.exe" /d everyone
echo y|cacls.exe "c:\1.exe" /d everyone
echo y|cacls.exe "c:\ntldr.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\fpt.exe" /d everyone
echo y|cacls.exe "C:\windows\BEGIN.BAT" /d everyone
echo y|cacls.exe "C:\windows\help.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\avwghst.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\HBKrnl.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\avwlist.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\gjcsczc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\jsqsbzc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\jsqxazc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\jsqzczc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kaqhlaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kawdiaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kvdxlis.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\raqjktl.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\rsmyjsp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\rsztnsp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\HBKrnl.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\wszjdax.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\3.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kapjgaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\rsjzasp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\avzxmst.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\okmhdaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kafykaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\rpcs.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\starwindserviceae.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\rsjzbsp.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\nndcompress.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\mszxyll32.dll" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kvdxsois.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kvdxmis.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\kkawdjaz.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\jsqxczc.exe" /d everyone
echo y|cacls.exe "c:\WINDOWS\system32\avwgjst.exe" /d everyone
reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v Wallpaper /d \\192.168.0.248\桌面\07.bmp /f
gpupdate /force
RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
cacls "C:\Documents and Settings\All Users\\\" /t /e /c /d administrators
@exit
|