1
+ @ echo off
2
+
3
+ echo " Windows???????? v0.1"
4
+ echo " ??:ym"
5
+
6
+ if exist d:\????\ (
7
+
8
+ echo
9
+
10
+ ) else (
11
+
12
+ md d:\????\
13
+
14
+ )
15
+
16
+ if not exist d:\????\ md d:\????\
17
+
18
+
19
+
20
+ echo " ??????"
21
+
22
+ systeminfo > d:\????\????.log
23
+
24
+ echo " ??????"
25
+
26
+ netstat -anb > d:\????\????.log
27
+
28
+ echo " ????"
29
+
30
+ tasklist& net start > d:\????\????.log
31
+
32
+ echo " ??????"
33
+
34
+ wmic process get name,executablepath,processid > d:\????\??????.log
35
+
36
+ echo " ??????"
37
+
38
+ net share > d:\????\??????.log
39
+
40
+ echo " ??????"
41
+
42
+ net user & net localgroup administrators > d:\????\??????.log
43
+
44
+ echo " ??????"
45
+
46
+ echo HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names [1 2 19]> d:\regg.ini& echo HKEY_LOCAL_MACHINE\SAM\SAM\ [1 2 19] >> d:\regg.ini & regini d:\regg.ini& reg query HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names > d:\????\??????.log& del d:\regg.ini
47
+
48
+ echo " ????????"
49
+
50
+ reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run & reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run > d:\????\????????.log
51
+
52
+ echo " ??????"
53
+
54
+ secedit /export /cfg LocalGroupPolicy& type LocalGroupPolicy > d:\????\??????.log
55
+
56
+ echo " IE???????"
57
+
58
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Internet" " Explorer\TypedURLs > d:\????\IE???????.log
59
+
60
+ echo " ???????"
61
+
62
+ reg query HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL /s /v DisPlayname > d:\????\???????.log
63
+
64
+ echo " ??????"
65
+
66
+ reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows" " NT\CurrentVersion\SvcHost /s /v netsvcs& reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows" " NT\CurrentVersion\SvcHost /s /v LocalService > d:\????\??????.log
67
+
68
+ echo " ????"
69
+
70
+ netstat -a > d:\????\????.log
71
+
72
+ echo " CMD??"
73
+
74
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU > d:\????\CMD??.log
75
+
76
+ echo " ??????"
77
+
78
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths > d:\????\??????.log
79
+
80
+ echo " ??????2"
81
+
82
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* /v * > d:\????\??????2.log
83
+
84
+ echo " ????"
85
+
86
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU > d:\????\????.log
87
+
88
+ echo " ????"
89
+
90
+ reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU > d:\????\????.log
91
+
92
+ echo " C???????"
93
+
94
+ echo " ????????????1,?????????0,?????2?,??????????"
95
+
96
+ echo " ???????!"
97
+
98
+ set /p var = find /c /i " this program" c:\* c:\Inetpub\* C:\Users\Administrator\Desktop\* c:\temp\* > d:\????\??????.log
99
+
100
+ %var%
101
+
102
+ if %ERRORLEVEL% == 0 goto yes
103
+
104
+ goto no
105
+
106
+ :yes
107
+
108
+ exit
109
+
110
+ :no
111
+
112
+ find /c /i " this program" c:\* c:\wmpub\* c:\Inetpub\* C:\Documents and Settings\Administrator\??\* > d:\????\??????.log
113
+ echo " *****************ym***********************************"
0 commit comments