China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-07-01 06:15
中国DOS联盟论坛 » 其它操作系统综合讨论区 » I just wrote a batch script, still need everyone to study together!! View 7,763 Replies 30
Floor 16 Posted 2006-06-11 01:31 ·  中国 河北 保定 移动
铂金会员
★★★★
网络独行侠
Credits 6,962
Posts 2,753
Joined 2003-04-16 00:00
23-year member
UID 1565
Gender Male
From 河北保定
Status Offline
From the description of the original poster, several doubts are found. Please the original poster can find the solution through these doubts:

1. I found that the original poster tried various methods, but did not see the original poster installing security patches for the system. I always think that for any virus and trojan horse, prevention is better than cure.

2. Since the machine has a hardware restore card, in principle, the system should not be afraid of being damaged by the virus. Just restart all machines and restore it, right?

3. Since this virus is spread through the weak password of the system and the default management share, why not remove the management share of all machines? This can be permanently realized by modifying the registry. For the specific method, please google.
偶只喜欢回答那些标题和描述都很清晰的帖子!
如想解决问题,请认真学习“这个帖子”和“这个帖子”并努力遵守,如果可能,请告诉更多的人!
Floor 17 Posted 2006-06-11 08:28 ·  中国 福建 泉州 电信
高级用户
★★
论坛灌水专业户
Credits 613
Posts 266
Joined 2006-04-19 22:47
20-year member
UID 54113
From 河南省
Status Offline
Reply to the above:
I often install security patches, but I don't know if there are new patches released recently. Thanks for the reminder!
The computer doesn't have a restore card, but has Restore Wizard installed, and it only protects the system drive. In fact, including Restore Wizard, restore cards, Freeze and other things are helpless against it.
It can't work normally without sharing here, so it's not feasible. Modify the registry? I tried deleting the registry startup items and forbidding the virus program from running.
This virus is really awesome!!
Alas, I cut off the network of some machines yesterday and killed the virus one by one. Now it seems there's nothing wrong, and the virus killing is in progress~~~
饮马恒河畔,剑指天山西,碎叶城揽月,库叶岛赏雪,黑海之滨垂钓,贝尔加湖面张弓;中南半岛访古,东京废墟祭祖!
Floor 18 Posted 2006-06-11 13:19 ·  中国 湖北 荆门 电信
荣誉版主
★★★
Credits 2,013
Posts 718
Joined 2006-02-18 07:07
20-year member
UID 50550
Status Offline
The sound of the wind and the cry of cranes make one terrified, and people talk about viruses with horror.

I don't want to say more about how to check and kill viruses. As for your situation, if you can set permissions properly, you should be able to solve the problem.

Set all the keys in the registry that may be used to start viruses to be forbidden to write. Set all the keys related to IE settings to be forbidden to write (it's best not to set the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings key to be forbidden to write, otherwise opening IE will be about 1 second slower than usual). Set the startup folder to be read-only and not writable. Except for some folders of software that may be updated under the C drive, all others are forbidden to write, especially the windows and system32 directories.
Floor 19 Posted 2006-06-12 12:46 ·  中国 福建 泉州 电信
高级用户
★★
论坛灌水专业户
Credits 613
Posts 266
Joined 2006-04-19 22:47
20-year member
UID 54113
From 河南省
Status Offline
Thanks to the moderator, it's almost cleared now, and we're strengthening protection.

Hope it will be peaceful from now on.

........................................
饮马恒河畔,剑指天山西,碎叶城揽月,库叶岛赏雪,黑海之滨垂钓,贝尔加湖面张弓;中南半岛访古,东京废墟祭祖!
Floor 20 Posted 2006-06-12 17:30 ·  IANA 局域网IP(Private-Use)
铂金会员
★★★★
Credits 7,493
Posts 2,672
Joined 2005-09-02 00:00
20-year member
UID 42173
Gender Male
Status Offline
Passing by

(Muttering to myself: I've always run naked, never been hit, never been hit, never been hit,......)

C:\>BLOG http://initiative.yo2.cn/
C:\>hh.exe ntcmds.chm::/ntcmds.htm
C:\>cmd /cstart /MIN "" iexplore "about:<bgsound src='res://%ProgramFiles%\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll/10/5432'>"
Floor 21 Posted 2006-06-12 18:30 ·  中国 福建 泉州 电信
高级用户
★★
论坛灌水专业户
Credits 613
Posts 266
Joined 2006-04-19 22:47
20-year member
UID 54113
From 河南省
Status Offline
Damn, someone dares to pass by my place!

This road was opened by me

This tree was planted by me

If you want to pass here

Leave toll money!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
饮马恒河畔,剑指天山西,碎叶城揽月,库叶岛赏雪,黑海之滨垂钓,贝尔加湖面张弓;中南半岛访古,东京废墟祭祖!
Floor 22 Posted 2006-06-13 12:10 ·  中国 广西 河池 电信
初级用户
Credits 80
Posts 29
Joined 2006-05-03 03:20
20-year member
UID 54852
Status Offline
We also got infected here. Finally, we reinstalled the system and did a full-disk clone to feel at ease. Too toxic!!!!!
Floor 23 Posted 2006-06-14 16:47 ·  中国 山西 太原 中移铁通
元老会员
★★★★
Batchinger
Credits 4,432
Posts 1,512
Joined 2002-10-18 00:00
23-year member
UID 19
Gender Male
Status Offline

───────────────── Moderation Record ──────────────────
Performed by: Will Sort
Operation: Move Topic: From DOS Batch Processing & Script Technology (Batch Processing Room)
Description: According to the topic content classification, more suitable to be posted in this forum area
───────────────── Moderation Record ──────────────────
※ Batchinger 致 Bat Fans:请访问 批处理编程的异类 ,欢迎交流与共享批处理编程心得!
Floor 24 Posted 2006-06-26 04:23 ·  中国 重庆 巴南区 电信
新手上路
Credits 2
Posts 1
Joined 2006-06-26 04:20
20-year member
UID 57565
From adf
Status Offline
NOD32 this antivirus software can kill logo_1
Floor 25 Posted 2006-06-26 13:57 ·  中国 安徽 芜湖 电信
高级用户
★★★
Credits 866
Posts 415
Joined 2005-12-04 11:19
20-year member
UID 46459
Status Offline
Sympathizing with the thread starter. Some viruses are indeed powerful, but as some netizens said, prevention is better than cure.
Floor 26 Posted 2006-06-26 16:17 ·  中国 上海 黄浦区 电信
金牌会员
★★★★
Credits 4,639
Posts 2,239
Joined 2005-01-30 00:00
21-year member
UID 35785
Gender Male
Status Offline
I just saw this post today. I haven't encountered the virus mentioned by the original poster. So I won't discuss it specifically. I'll just talk about my experience with antivirus and exchange with everyone. Also, please share your respective experiences.

First, talk about antivirus software.
Regarding which antivirus software is good, this has been a matter of debate. Some say AAA is the best and ZZZ is the worst, and vice versa. Some also say neither is good and XXX is the best. There are always several antivirus software that are relatively top in terms of the number of viruses detected, resource consumption, ease of use, etc. But my view is that the free ones are the best, and those with free updates are the best (including cracked versions).

Then talk about how to kill viruses.
Before talking about this, I always had an idea to say to everyone and even all in the IT industry: The current "virus" doesn't deserve to be called a virus and shouldn't be called a virus anymore. Why? Think about it. Originally, computer viruses borrowed the concept of biological viruses because their survival and behavior are extremely similar to biological viruses. First, it cannot exist alone and must be parasitic in normal files or the sectors used by the system, that is, it cannot exist as a single file. Because if it dared to exist as a single file, I could immediately delete it with "del"! So it must hide secretly.
In the Windows era, the situation is different. A virus can actually exist openly as one or several files! It dares to jump out! Why? This is caused by Windows! In DOS, there are not many places related to startup, and I can easily know where is abnormal. But in Windows, I thought I knew everything today, but one day I don't know where another place will pop up. Oh my god, I didn't expect this place is also related to startup?! In addition to the system's own startup, the startup of the resource manager and IE may all be used by viruses. And Microsoft has never clearly stated which files are related to the startup of the system and an application. I don't know if Microsoft's own engineers can make each item in the registry clear and explicit. Therefore, Windows itself is a huge place full of dirt! The current virus is precisely taking advantage of people's ignorance of system files so that it dares to exist as a file. Therefore, the current computer virus should not be called a virus, but should be called a bacterium, should be called a computer bacterium! (As far as I know, I am the first one to put forward this idea)
However, precisely because the current virus (let's call it by the habit for now) dares to exist as a file, it also enables us to remove it manually. I currently have only two types of viruses that cannot be removed manually in a virus-infected environment. One is 3721, and the other is a virus that replaces the most basic system files of Windows, that is, the system files that are also called in safe mode. The rest of the viruses can basically be manually deleted even in a virus-infected environment. Even if the virus files are not completely deleted, at least it can be made inactive, and then the antivirus software can be called to perform a full scan. The virus like smss.exe mentioned by sister afn, I have encountered it and it was removed manually.

Okay, let's stop talking big. If other people have any experiences and challenges, welcome to share and exchange.
Floor 27 Posted 2006-06-26 17:21 ·  中国 安徽 芜湖 电信
高级用户
★★★
Credits 866
Posts 415
Joined 2005-12-04 11:19
20-year member
UID 46459
Status Offline
That's wonderful, applause. "Whoosh whoosh whoosh........"
Floor 28 Posted 2006-06-26 17:35 ·  中国 福建 莆田 联通
中级用户
★★
DOS爱好者
Credits 213
Posts 99
Joined 2006-03-26 12:36
20-year member
UID 52807
Gender Male
Status Offline
Is the owner engaged in network management work?
Floor 29 Posted 2006-06-26 21:44 ·  中国 广东 广州 白云区 电信
荣誉版主
★★★
Credits 718
Posts 313
Joined 2005-09-26 00:00
20-year member
UID 42844
Gender Male
Status Offline
Nowadays, computer viruses shouldn't be called viruses, but should be called bacteria, should be called computer bacteria! (As far as I know, I was the first one to come up with this idea)


DOSforever is creative! But "germ" has divisions like "probiotics", while "virus" doesn't.
Floor 30 Posted 2006-06-26 22:18 ·  中国 上海 电信
金牌会员
★★★★
Credits 4,639
Posts 2,239
Joined 2005-01-30 00:00
21-year member
UID 35785
Gender Male
Status Offline
Hehe, what you said is right. But in my memory, there used to be a kind of virus that would clear several viruses when it activated, and it itself seemed to have no harm. I forgot what it was called.
Forum Jump: