@ECHO OFF ECHO RMGONERA.BAT -- W32/Gonera-A virus removal utility ECHO Version 1.00 ECHO Copyright (c) 2001, Sophos Plc, www.sophos.com ECHO. assoc .scr=txtfile REM If received as a text file rename to RMGONERA.BAT. REM Run by typing RMGONERA.BAT at a command prompt or double-clicking this file. if exist c:\windows\*.* goto do9x if exist d:\windows\*.* goto do9x if exist c:\winnt\system32\gone.scr attrib -r -h -s c:\winnt\system32\gone.scr if exist c:\mirc\remote32.ini attrib -r -h -s c:\mirc\remote32.ini if exist c:\mirc32\remote32.ini attrib -r -h -s c:\mirc32\remote32.ini if exist c:\progra~1\mirc\remote32.ini attrib -r -h -s c:\progra~1\mirc\remote32.ini if exist c:\progra~1\mirc32\remote32.ini attrib -r -h -s c:\progra~1\mirc32\remote32.ini if exist d:\winnt\system32\gone.scr attrib -r -h -s d:\winnt\system32\gone.scr if exist d:\mirc\remote32.ini attrib -r -h -s d:\mirc\remote32.ini if exist d:\mirc32\remote32.ini attrib -r -h -s d:\mirc32\remote32.ini if exist d:\progra~1\mirc\remote32.ini attrib -r -h -s d:\progra~1\mirc\remote32.ini if exist d:\progra~1\mirc32\remote32.ini attrib -r -h -s d:\progra~1\mirc32\remote32.ini if exist c:\winnt\system32\gone.scr del c:\winnt\system32\gone.scr if exist c:\mirc\remote32.ini del c:\mirc\remote32.ini if exist c:\mirc32\remote32.ini del c:\mirc32\remote32.ini if exist c:\progra~1\mirc\remote32.ini del c:\progra~1\mirc\remote32.ini if exist c:\progra~1\mirc32\remote32.ini del c:\progra~1\mirc32\remote32.ini if exist d:\winnt\system32\gone.scr del d:\winnt\system32\gone.scr if exist d:\mirc\remote32.ini del d:\mirc\remote32.ini if exist d:\mirc32\remote32.ini del d:\mirc32\remote32.ini if exist d:\progra~1\mirc\remote32.ini del d:\progra~1\mirc\remote32.ini if exist d:\progra~1\mirc32\remote32.ini del d:\progra~1\mirc32\remote32.ini goto doreg :do9x REM Create WININIT.INI to delete viral files if exist %windir%\wininit.bak del %windir%\wininit.bak if exist %windir%\wininit.ini move %windir%\wininit.ini %windir%\wininit.bak >nul echo [Rename] >%windir%\wininit.ini echo nul=c:\windows\system\gone.scr >>%windir%\wininit.ini echo nul=c:\mirc\remote32.ini >>%windir%\wininit.ini echo nul=c:\mirc32\remote32.ini >>%windir%\wininit.ini echo nul=c:\progra~1\mirc\remote32.ini >>%windir%\wininit.ini echo nul=c:\progra~1\mirc32\remote32.ini >>%windir%\wininit.ini echo nul=d:\windows\system\gone.scr >>%windir%\wininit.ini echo nul=d:\mirc\remote32.ini >>%windir%\wininit.ini echo nul=d:\mirc32\remote32.ini >>%windir%\wininit.ini echo nul=d:\progra~1\mirc\remote32.ini >>%windir%\wininit.ini echo nul=d:\progra~1\mirc32\remote32.ini >>%windir%\wininit.ini :doreg echo REGEDIT4 >%windir%\gonera.reg echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] >>%windir%\gonera.reg echo "c:\\windows\\system\\gone.scr"=- >>%windir%\gonera.reg echo "c:\\windows98\\system\\gone.scr"=- >>%windir%\gonera.reg echo "c:\\windows.000\\system\\gone.scr"=- >>%windir%\gonera.reg echo "d:\\windows\\system\\gone.scr"=- >>%windir%\gonera.reg echo "d:\\windows98\\system\\gone.scr"=- >>%windir%\gonera.reg echo "d:\\windows.000\\system\\gone.scr"=- >>%windir%\gonera.reg echo "c:\\winnt\\system32\\gone.scr"=- >>%windir%\gonera.reg echo "d:\\winnt\\system32\\gone.scr"=- >>%windir%\gonera.reg regedit /s %windir%\gonera.reg del %windir%\gonera.reg ECHO. ECHO. ECHO. Finished. ECHO. ECHO Now Scan this computer with an up-to-date copy of Sophos Anti-Virus and ECHO today's virus identity (IDE) files. ECHO.