⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 form1.frm

📁 Antivirus Description: It s a working antivirus or worm remover for most common virus. It dosen t
💻 FRM
📖 第 1 页 / 共 5 页
字号:

Private Sub DELcommons()
Dim delx As String
Dim delexe As String
Dim deldir As String
Dim souchk As String

For i = 0 To commonname.ListCount - 1

delexe = GetSystemDirectory & commonname.List(i)
    
souchk = Right(App.Path, 1)

    If souchk = "\" Then
        deldir = App.Path & "dels.exe /nologo /nw "
    Else
        deldir = App.Path & "\dels.exe /nologo /nw "
    End If


appnm = deldir & rtext & delexe & rtext

DOShell appnm, 0
Next i
DELcommons2
End Sub
Private Sub DELcommons2()
Dim delx As String
Dim delexe As String
Dim deldir As String
Dim souchk As String

For i = 0 To commonname.ListCount - 1

delexe = GetSystemDirectory & commonname.List(i)
    
souchk = Right(App.Path, 1)

    If souchk = "\" Then
        deldir = App.Path & "dels.exe /nologo /nw "
    Else
        deldir = App.Path & "\dels.exe /nologo /nw "
    End If


appnm = deldir & rtext & delexe & rtext
DOShell appnm, 0
Next i
DELETE_Run_and_Others
End Sub '----------------------------[[[[ Deleting Ends here ]]]]---



'-------------------------------------------------------------------------------------
'===================================================#### [First resistry settings ] ##
'-------------------------------------------------------------------------------------
Private Sub DELETE_Run_and_Others() '------------------[[[ First resistry settings ]]]

Dim x As Integer

For x = 0 To 10
'MsgBox x
'============================HKEY_CURRENT_USER============================================
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\RunOnce"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\RunOnceEx"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents"
DeleteKey HKEY_CURRENT_USER, "Software\Microsoft\Windows\CurrentVersion\Run"
'============================HKEY_LOCAL_MACHINE===========================================
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\RunOnce"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\RunOnceEx"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents"
DeleteKey HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run"
DeleteKey HKEY_LOCAL_MACHINE, "SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices"
DeleteKey HKEY_LOCAL_MACHINE, "SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce"
'=================================HKEY_USER=============================================
DeleteKey HKEY_USERS, ".DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run"


'====================================== All virus Reg here
'1 AUTOEXEC.COM
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
'2 KRAG
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "krag"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "krag"
'3 LILF
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Winsock2 driver"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Winsock2 driver"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce", "Winsock2 driver"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce", "Winsock2 driver"
'4 m1t8ta
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "amva"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "amva"
'5 RevMon
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SVCHOST"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SVCHOST"
'6 Setupexe
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MyApp"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MyApp"
'7 smss-funnymst
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Runonce"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Runonce"
'8 Setupmp4
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
'9 tip
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "RunJava2"
'10 system-4msamir
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS1"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS2"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS3"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS4"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Msmsgs"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS1"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS2"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS3"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "SYS4"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Msmsgs"
'11 SSVICHOSST
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "A:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "C:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "D:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "E:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "F:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "G:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "H:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "I:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "J:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "K:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "L:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "M:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "N:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "O:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "P:\SSVICHOSST.exe"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Yahoo Messengger"
DeleteValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon", "Shell"
SetKeyValue HKEY_CURRENT_USER, _
"SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" _
, "Shell", "Explorer.exe", REG_SZ

DeleteValue HKEY_USERS, _
"S-1-5-21-1343024091-1682526488-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run", "Yahoo Messengger"

DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "A:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "C:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "D:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "E:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "F:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "G:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "H:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "I:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "J:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "K:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "L:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "M:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "N:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "O:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"Software\Microsoft\Windows\ShellNoRoam\MUICache", "P:\SSVICHOSST.exe"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Yahoo Messengger"
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon", "Shell"
SetKeyValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" _
, "Shell", "Explorer.exe", REG_SZ
'Flashy Bot
DeleteValue HKEY_LOCAL_MACHINE, _
"System\controlSet001\Services", "Flashy Bot"
DeleteValue HKEY_CURRENT_USER, _
"System\controlSet001\Services", "Flashy Bot"
'12 KALSHI spammer trojan registry entry
DeleteValue HKEY_LOCAL_MACHINE, _
"System\controlSet001\Services", "MassSender"
'13 msblaster registry entry
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "windows auto update"
'14 welchia registry entry
DeleteValue HKEY_LOCAL_MACHINE, _
"SYSTEM\CurrentControlSet\Services", "RpcPatch"
DeleteValue HKEY_LOCAL_MACHINE, _
"SYSTEM\CurrentControlSet\Services", "RpcTftpd"

'15 p spider backdoor
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "mssysint"
        
'16 yaha worm
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MicrosoftServiceManager"
         
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MicrosoftServiceManager"
        
'17 lala backdoor
        
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "PNtask Services"

'18 nibu backdoor
DeleteValue HKEY_LOCAL_MACHINE, _
"\SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "load32"

'19 love virus registry entry
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MSKernel32"
                
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "Win32DLL"
                
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "WIN-BUGSFIX"
                
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "WWinFAT32=WinFAT32.EXE"
        
'20 cone keylogger registry entries
        
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects", "{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}"
        
DeleteValue HKEY_LOCAL_MACHINE, _
"CLASSES\CLSID", "{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}"

DeleteValue HKEY_LOCAL_MACHINE, _
"CLASSES\Interface", "{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}"

DeleteValue HKEY_LOCAL_MACHINE, _
"CLASSES\TypeLib", "{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}"

DeleteValue HKEY_LOCAL_MACHINE, _
"CLASSES\TypeLib", "{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}"
        
'21 datom worm
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "MSVXD"

'22 sircam worm
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices", "Driver32."
    
'23 intruzzo trojan
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "HPSFD %System%\GLIDELOAD.exe /s"
    
'24 sworpta trojan
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Internet Explorer\Main\", "Start Page"
        
DeleteValue HKEY_LOCAL_MACHINE, _
"SOFTWARE\Microsoft\Internet Explorer\Main\", "Startpagina"
    
'''''below is how to delete a full key put all full
'''''key deletions under this for easy reference

'25 sub seven registry removal
DeleteKey HKEY_LOCAL_MACHINE, "SOFTWARE\Microsoft\ENC"
    
'26 sircam worm
DeleteKey HKEY_LOCAL_MACHINE, "SOFTWARE\SirCam"
    
'27 irc rpc bot
DeleteKey HKEY_LOCAL_MACHINE, "SOFTWARE\TFTPD32"
    
'28 ms blast whole key kill?
DeleteKey HKEY_LOCAL_MACHINE, "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows auto update"
    
'29 sworpta trojan
DeleteKey HKEY_LOCAL_MACHINE, "HKEY_CURRENT_USER\Software\SWCaller\"

Next x
PID = "1"
ining_Write
'strtup
'End
killme
End Sub
Private Sub killme() '--------------------------------------------[[Shutdown Function]]
Dim deldir As String
Dim souchk As String
Dim ask
strtup
souchk = Right(App.Path, 1)
If souchk = "\" Then
deldir = App.Path & "sd

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -