Skip to content

Commit 55782c1

Browse files
author
InformationSecurity
authored
Add files via upload
1 parent 2ab849a commit 55782c1

File tree

1 file changed

+113
-0
lines changed

1 file changed

+113
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,113 @@
1+
@echo off
2+
3+
echo "Windows???????? v0.1"
4+
echo "??:ym"
5+
6+
if exist d:\????\ (
7+
8+
echo
9+
10+
) else (
11+
12+
md d:\????\
13+
14+
)
15+
16+
if not exist d:\????\ md d:\????\
17+
18+
19+
20+
echo "??????"
21+
22+
systeminfo >d:\????\????.log
23+
24+
echo "??????"
25+
26+
netstat -anb >d:\????\????.log
27+
28+
echo "????"
29+
30+
tasklist&net start >d:\????\????.log
31+
32+
echo "??????"
33+
34+
wmic process get name,executablepath,processid >d:\????\??????.log
35+
36+
echo "??????"
37+
38+
net share >d:\????\??????.log
39+
40+
echo "??????"
41+
42+
net user & net localgroup administrators >d:\????\??????.log
43+
44+
echo "??????"
45+
46+
echo HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names [1 2 19]>d:\regg.ini&echo HKEY_LOCAL_MACHINE\SAM\SAM\ [1 2 19] >>d:\regg.ini & regini d:\regg.ini&reg query HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names >d:\????\??????.log&del d:\regg.ini
47+
48+
echo "????????"
49+
50+
reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run & reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run >d:\????\????????.log
51+
52+
echo "??????"
53+
54+
secedit /export /cfg LocalGroupPolicy&type LocalGroupPolicy >d:\????\??????.log
55+
56+
echo "IE???????"
57+
58+
reg query HKEY_CURRENT_USER\Software\Microsoft\Internet" "Explorer\TypedURLs >d:\????\IE???????.log
59+
60+
echo "???????"
61+
62+
reg query HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL /s /v DisPlayname >d:\????\???????.log
63+
64+
echo "??????"
65+
66+
reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SvcHost /s /v netsvcs&reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SvcHost /s /v LocalService >d:\????\??????.log
67+
68+
echo "????"
69+
70+
netstat -a >d:\????\????.log
71+
72+
echo "CMD??"
73+
74+
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU >d:\????\CMD??.log
75+
76+
echo "??????"
77+
78+
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths >d:\????\??????.log
79+
80+
echo "??????2"
81+
82+
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* /v * >d:\????\??????2.log
83+
84+
echo "????"
85+
86+
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU >d:\????\????.log
87+
88+
echo "????"
89+
90+
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU >d:\????\????.log
91+
92+
echo "C???????"
93+
94+
echo "????????????1,?????????0,?????2?,??????????"
95+
96+
echo "???????!"
97+
98+
set /p var=find /c /i "this program" c:\* c:\Inetpub\* C:\Users\Administrator\Desktop\* c:\temp\* >d:\????\??????.log
99+
100+
%var%
101+
102+
if %ERRORLEVEL% == 0 goto yes
103+
104+
goto no
105+
106+
:yes
107+
108+
exit
109+
110+
:no
111+
112+
find /c /i "this program" c:\* c:\wmpub\* c:\Inetpub\* C:\Documents and Settings\Administrator\??\* >d:\????\??????.log
113+
echo "*****************ym***********************************"

0 commit comments

Comments
 (0)