SoFunction
Updated on 2025-04-08

Autorun's random 7-digit virus killing tool

<!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http:///TR/xhtml1/DTD/">
<html xmlns="http:///1999/xhtml">
<head>
<title>Virus killing tools named with seven letters</title>
<HTA:APPLICATION 
    APPLICATIONNAME="KILLVIRUS"
    border="thin" 
    borderstyle="normal" 
    caption="yes" 
    icon="" 
    maximizebutton="no"
    minimizebutton="yes"
    showintaskbar="yes" 
    singleinstance="yes"
    sysmenu="yes" 
    version="1.0" 
    windowState="normal"
>
<style type="text/css">
    body           {background-color:#FFF}
    body,input     {font:9pt tahoma}
    body a         {font-size:12px;text-decoration:none}
    body a:link    {color:#0000CC;text-decoration:none}
    body a:visited {color:#0000CC;text-decoration:none}
    fieldset       {height:230x}
    legend         {font-weight: bolder}
    #DataArea      {color:#FF0000}
    textarea       {scrollbar-face-color:#FFF;
                    scrollbar-arrow-color:#000;
                    scrollbar-base-color:#FFF; 
                    scrollbar-dark-shadow-color:##2D5B2D;
                   }
</style>
</head>

<script language="VBScript">

Sub Window_onLoad
 620,400
End Sub

Sub DONOW
= "Quick antivirus is underway...Please wait..."
End Sub

Sub DOEND
= "Virus removal was successfully removed. If you find that there is a virus that cannot be removed by this special killer, please submit the sample: ycosxhack@, compress and encrypt virus."
End Sub

Sub KILLVIRUS
DONOW
on error resume next
msgbox "This special kill is made by the cosine function, click to start to kill viruses.",64,"Autorun random seven-letter virus kill"
set w=getobject("winmgmts:")
set p=("select * from win32_process where name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name='' or name=''") 
for each i in p
 
next
set fso=createobject("")
set del=createobject("")
dim d(16)
dim v(16)
d(0)=("%SystemRoot%\system32\")
d(1)=("%SystemRoot%\system32\")
d(2)=("%SystemRoot%\system32\")
d(3)=("%SystemRoot%\system32\")
d(4)=("%SystemRoot%\system32\")
d(5)=("%SystemRoot%\system32\")
d(6)=("%SystemRoot%\system32\")
d(7)=("%SystemRoot%\system32\")
d(8)=("%SystemRoot%\system32\")
d(9)=("%SystemRoot%\system32\")
d(10)=("%SystemRoot%\system32\")
d(11)=("%SystemRoot%\system32\")
d(12)=("%SystemRoot%\system32\")
d(13)=("%SystemRoot%\system32\")
d(14)=("%SystemRoot%\system32\")
d(15)=("%SystemRoot%\system32\")
for i=0 to 15
set v(i)=(d(i))
v(i).attributes=0
v(i).delete
next
set fso=createobject("")
set drvs=
for each drv in drvs
if =1 or =2 or =3 or =4 then
set w=(&":\")
=0

set w_1=(&":\")
w_1.attributes=0
w_1.delete
set w_2=(&":\")
w_2.attributes=0
w_2.delete
set w_3=(&":\")
w_3.attributes=0
w_3.delete
set w_3=(&":\")
w_3.attributes=0
w_3.delete
set w_4=(&":\")
w_4.attributes=0
w_4.delete
set u=(&":\")
=0

end if
next
set reg=createobject("")
 "HKLM\SYSTEM\CurrentControlSet\Services\AVP\Start",2,"REG_DWORD"
 "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start",2,"REG_DWORD"
 "HKLM\SYSTEM\CurrentControlSet\Services\helpsvc\Start",2,"REG_DWORD"
 "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Start",2,"REG_DWORD"
 "HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start",2,"REG_DWORD"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue",1,"REG_DWORD"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\DefaultValue",2,"REG_DWORD"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN\CheckedValue",2,"REG_DWORD"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN\DefaultValue",2,"REG_DWORD"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\UncheckedValue",1,"REG_DWORD"

 "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hhsonxn"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kocmbcd"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\haqeyfy"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vlskjgs"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\udnnnvq"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uragvod"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cfrxjwg"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nqgphqd"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmxpbpl"
 "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dnpsalq"

 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\Debugger","NoVirus","REG_SZ"
set fso=nothing
DOEND
End Sub

Sub EXITKILL
()
End Sub

</script>

<body>
<input type="button" value="KillVirus" onClick="KILLVIRUS">
<input type="button" value="My BLOG" onClick="('/ycosxhack')">
<input type="button" value="EXIT" onClick="EXITKILL">
<------------------------------------------------------------------------------------------------------------------------------
<p><span id=DataArea>Click KillVirus to start antivirus…</span><p>
<fieldset>
<legend>- Read Me First -</legend>
<textarea  style="border:0; background-color:#FFFFFF; width:98%; height:226px;">
Autorun's random seven-letter virus kill

1. Special killing can currently completely detect viruses that are spread through mobile disks! These are all variants of similar viruses. When encountering new variants, I will continue to update the antivirus instructions.

2. If you are a different variant of Virus. or *-Downloader., running this kill will temporarily solve some problems. You can send virus samples to this email address ycosxhack@ so that I can update the antivirus command.

3. When reprinting the source code of this special kill, please be sure to maintain the integrity of the source code...


BY Cosine Function June 7, 2007 /ycosxhack <-- My Blog
</textarea>
</fieldset>
</body>
</html>
Package file download