![]() |
中国DOS联盟-- 联合DOS 推动DOS 发展DOS --联盟域名:www.cn-dos.net 论坛域名:www.cn-dos.net/forum |
| 游客 | 登录 | 注册 | 会员 | 搜索 | 中国DOS联盟 |
|
中国DOS联盟论坛 现在时间是 2026-09-25 03:13 |
共 47,813 主题排行 / 349,918 发帖 / 今日 1 篇 / 48,274 会员排行 |
| DOS批处理 & 脚本技术(批处理室) » 防毒第一策略→锁定注册表启动项→VBS版 |
| 可打印版本 6,040 / 16 |
| 第1楼 baomaboy | 发表于 2007-03-17 11:59 |
| 银牌会员 发帖 554 积分 1,513 | |
|
防毒第一策略→锁定注册表启动项→VBS版 大家都知道病毒要取得启动权才能发挥作用,所以注册表中的Run项就成了病毒的老巢,这个脚本就是为Run项加把锁。当然安装自己认可的软件(如杀软)时还可以随时解锁。(因为杀软也需要入驻自启动项)
推荐如我等菜鸟使用,如果老鸟象我一样懒图方便的话……^_^ 安装完成后自动锁定Run启动项(包括HKCU和HKLM)和Runonce项 因为此功能不经常操作所以只把菜单做在了“我的电脑”右键中,如下图: 动态显示自动判断切换 锁定/释放 状态。 [ Last edited by baomaboy on 2007-5-17 at 04:48 PM ] 附件 LockUp_Registry.rar (39.45 KiB) 1.GIF (19.37 KiB) |
|
| 第2楼 lxmxn | 发表于 2007-03-17 12:01 |
| 版主 发帖 4,938 积分 11,386 | |
|
不错,顶之,看来兄对VBS和注册表颇有研究哇。 |
|
| 第3楼 baomaboy | 发表于 2007-03-17 12:10 |
| 银牌会员 发帖 554 积分 1,513 | |
Originally posted by lxmxn at 2007-3-17 12:01: lxmxn兄抬爱了,向你学习才是真,经常看本版看得出lxmxn兄过人之处尤其乐于助人之热心! |
|
| 第4楼 namejm | 发表于 2007-03-17 12:14 |
| 荣誉版主 发帖 1,737 积分 5,226 来自 成都 | |
|
功能确实不错,注册表研究得比较深入啊,只是,都是加密后的代码,是个遗憾。
|
|
| 第5楼 lxmxn | 发表于 2007-03-17 12:18 |
| 版主 发帖 4,938 积分 11,386 | |
Originally posted by baomaboy at 2007-3-16 23:10: 兄过讲了啊,惭愧,我也是个新手而已,也没有什么过人之处的。 下了附件并没有及时的参看里面东西,看了版主的回帖之后才知道加密了,兄不妨将代码传上来供大伙学习学习。 |
|
| 第6楼 SAtANly | 发表于 2007-03-17 12:52 |
| 新手上路 发帖 4 积分 8 | |
|
嗯嗯,
在下也想一看! 等积分够了才能下!呵呵~! |
|
| 第7楼 baomaboy | 发表于 2007-03-17 13:04 |
| 银牌会员 发帖 554 积分 1,513 | |
|
To namejm lxmxn SAtANly实在是我得代码可读性太差而羞于见人啊,不是科班出身,也没系统学习过……
写了不少代码,其中需要设置不同的变量和赋值,所以代码中有很多此处不需要得变量赋值。没办法啊,写一个东西添个新变量,图省事当成模版用了,写别的新东西都是直接复制然后修改^_^
[ Last edited by baomaboy on 2008-3-24 at 10:01 PM ] |
|
| 第8楼 youxi01 | 发表于 2007-03-17 14:20 |
| 高级用户 发帖 247 积分 846 来自 湖南==》广东 | |
|
终于贴出 源码 来了啊,那段加密的代码看的好 晕 啊,好久没有接触过vbs了。看了半天得出了一点点东东,惭愧啊!
|
|
| 第9楼 baomaboy | 发表于 2007-03-17 14:41 |
| 银牌会员 发帖 554 积分 1,513 | |
|
呵呵 对不起大家啊 因为发源码前又做了下调试 修改了一处 忘了恢复回去了
If (FSO.FileExists(FSO.BuildPath(OtherFilePath,OtherFileName)))=false Then ”=false“ 要删掉。 |
|
| 第10楼 baomaboy | 发表于 2007-03-17 14:50 |
| 银牌会员 发帖 554 积分 1,513 | |
Originally posted by youxi01 at 2007-3-17 14:20: |
|
| 第11楼 godicozy | 发表于 2007-03-18 04:52 |
| 新手上路 发帖 5 积分 10 | |
|
好长啊 ·· 读不懂。。
|
|
| 第12楼 slore | 发表于 2007-03-18 05:07 |
| 铂金会员 发帖 2,478 积分 5,212 | |
|
regini注册表权限设置
cacls文件权限设置 |
|
| 第13楼 baomaboy | 发表于 2007-03-18 05:19 |
| 银牌会员 发帖 554 积分 1,513 | |
Originally posted by slore at 2007-3-18 05:07: 谢谢slore,我去试下, 这样就可以加入判断分区类型决定是否执行cacls对文件权限的操作的代码了。 |
|
| 第14楼 kich | 发表于 2007-04-07 05:18 |
| 中级用户 发帖 168 积分 397 | |
|
注册表权限设置regini,到底要怎么操作呢?
Ps:baoma兄的代码好是好,不过不适合人工阅读,过多常量,有时候还有不用的常量和变量! 读起来很吃力!看了半天,发现这个变量到最后没有用!!! |
|
| 第15楼 baomaboy | 发表于 2007-04-07 06:36 |
| 银牌会员 发帖 554 积分 1,513 | |
Originally posted by kich at 2007-4-7 05:18: 使用方法: regini regset.ini regset.ini内容 把run项设为只允许system控制 其他用户不可控制 为控制参数 其他参数看下面的帮助 usage: REGINI textFiles... where: -m specifies a remote windows NT machine whose registry is to be manipula ted. -h specifies a specify local hive to manipulate. -w specifies the paths to a windows 95 system.dat and user.dat files -i n specifies the display indentation multiple. Default is 4 -o outputWidth specifies how wide the output is to be. By default the outputWidth is set to the width of the console window if standard output has not been redirected to a file. In the latter case, an outputWidth of 240 is used. -b specifies that REGINI should be backward compatible with older versions of REGINI that did not strictly enforce line continuations and quoted strings Specifically, REG_BINARY, REG_RESOURCE_LIST and REG_RESOURCE_REQUIREMENTS_LIST data types did not need line continuations after the first number that gave the size of the data. It just kept looking on following lines until it found enough data values to equal the data length or hit invalid input. Quoted strings were only allowed in REG_MULTI_SZ. They could not be specified around key or value names, or around values for REG_SZ or REG_EXPAND_SZ Finally, the old REGINI did not support the semicolon as an end of line comment character. textFiles is one or more ANSI or Unicode text files with registry data. The easiest way to understand the format of the input textFile is to use the REGDMP command with no arguments to dump the current contents of your NT Registry to standard out. Redirect standard out to a file and this file is acceptable as input to REGINI Some general rules are: Semicolon character is an end-of-line comment character, provided it is the first non-blank character on a line Backslash character is a line continuation character. All characters from the backslash up to but not including the first non-blank character of the next line are ignored. If there is more than one space before the line continuation character, it is replaced by a single space. Indentation is used to indicate the tree structure of registry keys The REGDMP program uses indentation in multiples of 4. You may use hard tab characters for indentation, but embedded hard tab characters are converted to a single space regardless of their position Values should come before child keys, as they are associated with the previous key at or above the value's indentation level. For key names, leading and trailing space characters are ignored and not included in the key name, unless the key name is surrounded by quotes. Imbedded spaces are part of a key name. Key names can be followed by an Access Control List (ACL) which is a series of decimal numbers, separated by spaces, bracketed by a square brackets (e.g. ). The valid numbers and their meanings are: 1 - Administrators Full Access 2 - Administrators Read Access 3 - Administrators Read and Write Access 4 - Administrators Read, Write and Delete Access 5 - Creator Full Access 6 - Creator Read and Write Access 7 - World Full Access 8 - World Read Access 9 - World Read and Write Access 10 - World Read, Write and Delete Access 11 - Power Users Full Access 12 - Power Users Read and Write Access 13 - Power Users Read, Write and Delete Access 14 - System Operators Full Access 15 - System Operators Read and Write Access 16 - System Operators Read, Write and Delete Access 17 - System Full Access 18 - System Read and Write Access 19 - System Read Access 20 - Administrators Read, Write and Execute Access 21 - Interactive User Full Access 22 - Interactive User Read and Write Access 23 - Interactive User Read, Write and Delete Access |
|
| 1 2 下一页 |
|
[ 联系联盟系统管理团队 -
中国DOS联盟 -
标准版 ] Sponsored by ifanr Inc | © 2001–2023 |