Remover for Stupid Worms
The worms that infect windows are really funny.
Kinza, IPH, Boot.vbs... what not...
Simple and Stupid worms... that make Windows go crazy..
I studied them, got 'inspired' by removal tools and tried some more... and here i give you a 'open source' .bat file that would remove those stupid stuffs...
here is the file: www.parikrama.net.np/worm_buster.bat
download the file and run it..
here is the thing it does...
cd\
shutdown -a
taskkill /f /im wproxp.exe
taskkill /f /im isetup.exe
taskkill /f /im imapd.exe
taskkill /f /im dxdlg.exe
taskkill /f /im imapdb.exe
taskkill /f /im imapd.exe
taskkill /f /im imapdb.exe
taskkill /f /im scvvhsot.exe
taskkill /f /im wscript.exe
taskkill /f /im Kinza.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f /d "%windir%\system32\userinit.exe",
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /f /d "explorer.exe"
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_Binary /v NoDriveAutoRun /f /d ffffff03
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_dword /v NoDriveTypeAutoRun /f /d 36
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_dword /v NoFolderOptions /f /d 0
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /t Reg_dword /v DisbleRegistryTools /f /d 0
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /t Reg_dword /v DisableTaskMgr /f /d 0
del /a /f /s boot.vbs
del /a /f /s virusremoval.bat
del /a /f /s wproxp.exe
del /a /f /s isetup.exe
del /a /f /s imapd.exe
del /a /f /s ActMon.ini
del /a /f /s dxdlg.exe
del /a /f /s imapde.dll
del /a /f /s imapdd.dll
del /a /f /s imapdc.dll
del /a /f /s imapdb.exe
del /a /f /s imapd.exe
del /a /f /s imapdb.dll
del /a /f /s imapdb.exe
del /a /f /s Kinza.exe
del /a /f /s iph.exe
del /a /f /s system.bat
del /a /f /s autorun.inf
del /a /f /s semiantivirus.vbs
_______________________
Initially it kills the processes.. then activates the Folder Options, unlocks the registry and task manager
Then it searches and kills all the worms found.
:)
Kinza, IPH, Boot.vbs... what not...
Simple and Stupid worms... that make Windows go crazy..
I studied them, got 'inspired' by removal tools and tried some more... and here i give you a 'open source' .bat file that would remove those stupid stuffs...
here is the file: www.parikrama.net.np/worm_buster.bat
download the file and run it..
here is the thing it does...
cd\
shutdown -a
taskkill /f /im wproxp.exe
taskkill /f /im isetup.exe
taskkill /f /im imapd.exe
taskkill /f /im dxdlg.exe
taskkill /f /im imapdb.exe
taskkill /f /im imapd.exe
taskkill /f /im imapdb.exe
taskkill /f /im scvvhsot.exe
taskkill /f /im wscript.exe
taskkill /f /im Kinza.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
taskkill /f /im iph.exe
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /f /d "%windir%\system32\userinit.exe",
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /f /d "explorer.exe"
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_Binary /v NoDriveAutoRun /f /d ffffff03
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_dword /v NoDriveTypeAutoRun /f /d 36
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /t Reg_dword /v NoFolderOptions /f /d 0
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /t Reg_dword /v DisbleRegistryTools /f /d 0
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /t Reg_dword /v DisableTaskMgr /f /d 0
del /a /f /s boot.vbs
del /a /f /s virusremoval.bat
del /a /f /s wproxp.exe
del /a /f /s isetup.exe
del /a /f /s imapd.exe
del /a /f /s ActMon.ini
del /a /f /s dxdlg.exe
del /a /f /s imapde.dll
del /a /f /s imapdd.dll
del /a /f /s imapdc.dll
del /a /f /s imapdb.exe
del /a /f /s imapd.exe
del /a /f /s imapdb.dll
del /a /f /s imapdb.exe
del /a /f /s Kinza.exe
del /a /f /s iph.exe
del /a /f /s system.bat
del /a /f /s autorun.inf
del /a /f /s semiantivirus.vbs
_______________________
Initially it kills the processes.. then activates the Folder Options, unlocks the registry and task manager
Then it searches and kills all the worms found.
:)
Comments